Oval Definition:oval:org.opensuse.security:def:81419
Revision Date:2017-06-19Version:1
Title:Security update for netpbm (Moderate)
Description:

This update for netpbm fixes the following issues:

Security bugs: * CVE-2017-2586: A NULL pointer dereference in stringToUint function could lead to a denial of service (abort) problem when processing malformed images. [bsc#1024292] * CVE-2017-2581: A out-of-bounds write in writeRasterPbm() could be used by attackers to crash the decoder or potentially execute code. [bsc#1024287] * CVE-2017-2587: A insufficient size check of memory allocation in createCanvas() function could be used for a denial of service attack (memory exhaustion) [bsc#1024294]
Family:unixClass:patch
Status:Reference(s):1024287
1024292
1024294
CVE-2017-2581
CVE-2017-2586
CVE-2017-2587
SUSE-SU-2017:1603-1
Platform(s):SUSE Linux Enterprise Server 12 SP2
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND Package Information
  • libnetpbm11-10.66.3-7.1 is installed
  • OR libnetpbm11-32bit-10.66.3-7.1 is installed
  • OR netpbm-10.66.3-7.1 is installed
  • BACK