Revision Date: | 2018-12-19 | Version: | 1 |
Title: | Security update for ovmf (Moderate) |
Description: |
This update for ovmf fixes the following issues:
Security issues fixed:
- CVE-2018-3613: Fixed AuthVariable Timestamp zeroing issue on APPEND_WRITE (bsc#1115916). - CVE-2017-5731: Fixed privilege escalation via processing of malformed files in TianoCompress.c (bsc#1115917). - CVE-2017-5732: Fixed privilege escalation via processing of malformed files in BaseUefiDecompressLib.c (bsc#1115917). - CVE-2017-5733: Fixed privilege escalation via heap-based buffer overflow in MakeTable() function (bsc#1115917). - CVE-2017-5734: Fixed privilege escalation via stack-based buffer overflow in MakeTable() function (bsc#1115917). - CVE-2017-5735: Fixed privilege escalation via heap-based buffer overflow in Decode() function (bsc#1115917).
Non security issues fixed:
- Fixed an issue with the default owner of PK/KEK/db/dbx and make the auto-enrollment only happen at the very first time. (bsc#1117998)
|
Family: | unix | Class: | patch |
Status: | | Reference(s): | 1115916 1115917 1117998 CVE-2017-5731 CVE-2017-5732 CVE-2017-5733 CVE-2017-5734 CVE-2017-5735 CVE-2018-3613 SUSE-SU-2018:4194-1
|
Platform(s): | SUSE Linux Enterprise Desktop 12 SP4
| Product(s): | |
Definition Synopsis |
SUSE Linux Enterprise Desktop 12 SP4 is installed AND qemu-ovmf-x86_64-2017+git1510945757.b2662641d5-3.5.1 is installed
|