FlawAtlas
Search the atlas
SUSE-SU-2019:0839-1 Not scored

Security update for file

This update for file fixes the following issues: The following security vulnerabilities were addressed: - Fixed an out-of-bounds read in the function do_core_note in readelf.c, which allowed remote attackers to cause a denial of service (application crash) via a crafted ELF file (bsc#1096974 CVE-2018-10360). - CVE-2019-8905: Fixed a stack-based buffer over-read in do_core_note in readelf.c (bsc#1126118) - CVE-2019-8906: Fixed an out-of-bounds read in do_core_note in readelf. c (bsc#1126119) - CVE-2019-8907: Fixed a stack corruption in do_core_note in readelf.c (bsc#1126117)

Exploit probability Not scored
Published April 2, 2019
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Desktop 12 SP3 file
SUSE:Linux Enterprise Desktop 12 SP4 file
SUSE:Linux Enterprise Server 12 SP3 file
SUSE:Linux Enterprise Server 12 SP4 file
SUSE:Linux Enterprise Server for SAP Applications 12 SP3 file
SUSE:Linux Enterprise Server for SAP Applications 12 SP4 file
SUSE:Linux Enterprise Software Development Kit 12 SP3 file
SUSE:Linux Enterprise Software Development Kit 12 SP3 python-magic
SUSE:Linux Enterprise Software Development Kit 12 SP4 file
SUSE:Linux Enterprise Software Development Kit 12 SP4 python-magic

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2019:0839-1

This update for file fixes the following issues: The following security vulnerabilities were addressed: - Fixed an out-of-bounds read in the function do_core_note in readelf.c, which allowed remote attackers to cause a denial of service (application crash) via a crafted ELF file (bsc#1096974 CVE-2018-10360). - CVE-2019-8905: Fixed a stack-based buffer over-read in do_core_note in readelf.c (bsc#1126118) - CVE-2019-8906: Fixed an out-of-bounds read in do_core_note in readelf. c (bsc#1126119) - CVE-2019-8907: Fixed a stack corruption in do_core_note in readelf.c (bsc#1126117)

View original source

05 / REFERENCES

Further evidence