FlawAtlas
Search the atlas
SUSE-SU-2016:2397-1 Not scored

Security update for flex, at, bogofilter, cyrus-imapd, kdelibs4, libQtWebKit4, libbonobo, mdbtools, netpbm, openslp, sgmltool, virtuoso, libqt5-qtwebkit

Various packages included vulnerable parsers generated by 'flex'. This update provides a fixed 'flex' package and also rebuilds of packages that might have security issues caused by the auto generated code. Flex itself was updated to fix a buffer overflow in the generated scanner (bsc#990856, CVE-2016-6354) Packages that were rebuilt with the fixed flex: - at - bogofilter - cyrus-imapd - kdelibs4 - libQtWebKit4 - libbonobo - mdbtools - netpbm - openslp - sgmltool - virtuoso Also libqt5-qtwebkit received an additional security fix: - CVE-2015-8079: QtWebKit logs visited URLs to WebpageIcons.db in private browsing mode (bsc#954210).

Exploit probability Not scored
Published September 27, 2016
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Desktop 12 SP1 at
SUSE:Linux Enterprise Desktop 12 SP1 bogofilter
SUSE:Linux Enterprise Desktop 12 SP1 kdelibs4
SUSE:Linux Enterprise Desktop 12 SP1 libQtWebKit4
SUSE:Linux Enterprise Desktop 12 SP1 libbonobo
SUSE:Linux Enterprise Desktop 12 SP1 netpbm
SUSE:Linux Enterprise Desktop 12 SP1 openslp
SUSE:Linux Enterprise Server 12 SP1 at
SUSE:Linux Enterprise Server 12 SP1 cyrus-imapd
SUSE:Linux Enterprise Server 12 SP1 flex
SUSE:Linux Enterprise Software Development Kit 12 SP1 libbonobo
SUSE:Linux Enterprise Server 12 SP1 kdelibs4
SUSE:Linux Enterprise Server 12 SP1 libQtWebKit4
SUSE:Linux Enterprise Server 12 SP1 libbonobo
SUSE:Linux Enterprise Server 12 SP1 netpbm
SUSE:Linux Enterprise Server 12 SP1 openslp
SUSE:Linux Enterprise Server for SAP Applications 12 SP1 at
SUSE:Linux Enterprise Server for SAP Applications 12 SP1 cyrus-imapd
SUSE:Linux Enterprise Server for SAP Applications 12 SP1 flex
SUSE:Linux Enterprise Server for SAP Applications 12 SP1 kdelibs4
SUSE:Linux Enterprise Server for SAP Applications 12 SP1 libQtWebKit4
SUSE:Linux Enterprise Server for SAP Applications 12 SP1 libbonobo
SUSE:Linux Enterprise Server for SAP Applications 12 SP1 netpbm
SUSE:Linux Enterprise Server for SAP Applications 12 SP1 openslp
SUSE:Linux Enterprise Software Development Kit 12 SP1 flex
SUSE:Linux Enterprise Software Development Kit 12 SP1 libQtWebKit4
SUSE:Linux Enterprise Software Development Kit 12 SP1 mdbtools
SUSE:Linux Enterprise Software Development Kit 12 SP1 netpbm
SUSE:Linux Enterprise Software Development Kit 12 SP1 openslp
SUSE:Linux Enterprise Software Development Kit 12 SP1 sgmltool
SUSE:Linux Enterprise Workstation Extension 12 SP1 bogofilter

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2016:2397-1

Various packages included vulnerable parsers generated by 'flex'. This update provides a fixed 'flex' package and also rebuilds of packages that might have security issues caused by the auto generated code. Flex itself was updated to fix a buffer overflow in the generated scanner (bsc#990856, CVE-2016-6354) Packages that were rebuilt with the fixed flex: - at - bogofilter - cyrus-imapd - kdelibs4 - libQtWebKit4 - libbonobo - mdbtools - netpbm - openslp - sgmltool - virtuoso Also libqt5-qtwebkit received an additional security fix: - CVE-2015-8079: QtWebKit logs visited URLs to WebpageIcons.db in private browsing mode (bsc#954210).

View original source

05 / REFERENCES

Further evidence