Lucene search

K
suseSuseSUSE-SU-2022:1277-1
HistoryApr 20, 2022 - 12:00 a.m.

Security update for dcraw (moderate)

2022-04-2000:00:00
lists.opensuse.org
25
dcraw
update
vulnerabilities
denial of service
floating point exception
information disclosure
buffer overflow
application crash
code execution
suse
opensuse leap

EPSS

0.009

Percentile

82.3%

An update that fixes 11 vulnerabilities is now available.

Description:

This update for dcraw fixes the following issues:

  • CVE-2017-13735: Fixed a denial of service issue due to a floating point
    exception (bsc#1056170).
  • CVE-2017-14608: Fixed an invalid memory access that could lead to
    information disclosure or denial of service (bsc#1063798).
  • CVE-2018-19655: Fixed a buffer overflow that could lead to an
    application crash (bsc#1117896).
  • CVE-2018-5801: Fixed an invalid memory access that could lead to denial
    of service (bsc#1084690).
  • CVE-2018-5805: Fixed a buffer overflow that could lead to an application
    crash (bsc#1097973).
  • CVE-2018-5806: Fixed an invalid memory access that could lead to denial
    of service (bsc#1097974).
  • CVE-2018-19565: Fixed an invalid memory access that could lead to
    information disclosure or denial of service (bsc#1117622).
  • CVE-2018-19566: Fixed an invalid memory access that could lead to
    information disclosure or denial of service (bsc#1117517).
  • CVE-2018-19567: Fixed a denial of service issue due to a floating point
    exception (bsc#1117512).
  • CVE-2018-19568: Fixed a denial of service issue due to a floating point
    exception (bsc#1117436).
  • CVE-2021-3624: Fixed a buffer overflow that could lead to code execution
    or denial of service (bsc#1189642).

Non-security fixes:

  • Updated to version 9.28.0.

Patch Instructions:

To install this SUSE Security Update use the SUSE recommended installation methods
like YaST online_update or “zypper patch”.

Alternatively you can run the command listed for your product:

  • openSUSE Leap 15.4:

    zypper in -t patch openSUSE-SLE-15.4-2022-1277=1

  • openSUSE Leap 15.3:

    zypper in -t patch openSUSE-SLE-15.3-2022-1277=1

OSVersionArchitecturePackageVersionFilename
openSUSE Leap15.4aarch64< - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64):- openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64):.aarch64.rpm
openSUSE Leap15.4ppc64le< - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64):- openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64):.ppc64le.rpm
openSUSE Leap15.4s390x< - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64):- openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64):.s390x.rpm
openSUSE Leap15.4x86_64< - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64):- openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64):.x86_64.rpm
openSUSE Leap15.4noarch< - openSUSE Leap 15.4 (noarch):- openSUSE Leap 15.4 (noarch):.noarch.rpm
openSUSE Leap15.3aarch64< - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):.aarch64.rpm
openSUSE Leap15.3ppc64le< - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):.ppc64le.rpm
openSUSE Leap15.3s390x< - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):.s390x.rpm
openSUSE Leap15.3x86_64< - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):.x86_64.rpm
openSUSE Leap15.3noarch< - openSUSE Leap 15.3 (noarch):- openSUSE Leap 15.3 (noarch):.noarch.rpm