Oval Definition:oval:org.opensuse.security:def:63719
Revision Date:2020-12-01Version:1
Title:Security update for netpbm (Moderate)
Description:

This update for netpbm fixes the following issues:

Security issues fixed:

- CVE-2018-8975: The pm_mallocarray2 function allowed remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file (bsc#1086777). - CVE-2017-2579: Fixed out-of-bounds read in expandCodeOntoStack() (bsc#1024288). - CVE-2017-2580: Fixed out-of-bounds write of heap data in addPixelToRaster() function (bsc#1024291).

- create netpbm-vulnerable subpackage and move pstopnm there (bsc#1136936)

Family:unixClass:patch
Status:Reference(s):1024288
1024291
1086777
1089524
1109663
1109847
1111498
1117025
1117382
1119687
1120658
1122000
1122344
1123333
1123892
1125352
1131576
1134078
1136572
1136936
1137825
1138459
1160613
1160614
1163749
1172515
1173257
1176315
1178593
CVE-2017-18926
CVE-2017-2579
CVE-2017-2580
CVE-2018-1000802
CVE-2018-14647
CVE-2018-20346
CVE-2018-20506
CVE-2018-8975
CVE-2019-10160
CVE-2019-12387
CVE-2019-6454
CVE-2019-6470
CVE-2019-9232
CVE-2019-9433
CVE-2020-14019
CVE-2020-17507
CVE-2020-7106
openSUSE-SU-2019:1760-1
openSUSE-SU-2020:0654-1
openSUSE-SU-2020:1156-1
openSUSE-SU-2020:1568-1
SUSE-SU-2019:0428-1
SUSE-SU-2019:0913-1
SUSE-SU-2019:1645-1
SUSE-SU-2019:2053-1
SUSE-SU-2019:2727-1
SUSE-SU-2020:0459-1
Platform(s):openSUSE Leap 15.1
openSUSE Leap 15.2
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server 12 SP4-ESPOS
Product(s):
Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • python-Twisted-17.9.0-lp151.3.3 is installed
  • OR python-Twisted-doc-17.9.0-lp151.3.3 is installed
  • OR python2-Twisted-17.9.0-lp151.3.3 is installed
  • OR python3-Twisted-17.9.0-lp151.3.3 is installed
  • Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • python-rtslib-fb-2.1.73-lp152.2.3 is installed
  • OR python2-rtslib-fb-2.1.73-lp152.2.3 is installed
  • OR python3-rtslib-fb-2.1.73-lp152.2.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • libnetpbm11-10.66.3-8.7 is installed
  • OR libnetpbm11-32bit-10.66.3-8.7 is installed
  • OR netpbm-10.66.3-8.7 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-ESPOS is installed
  • AND Package Information
  • libraptor2-0-2.0.15-5.3 is installed
  • OR raptor-2.0.15-5.3 is installed
  • BACK