Security update for ovmf
This update for ovmf fixes the following issues: Security issues fixed: - CVE-2019-14563: Fixed a memory corruption caused by insufficient numeric truncation (bsc#1163959). - CVE-2019-14553: Fixed the TLS certification verification in HTTPS-over-IPv6 boot sequences (bsc#1153072). - CVE-2019-14559: Fixed a remotely exploitable memory leak in the ARP handling code (bsc#1163927). - CVE-2019-14575: Fixed an insufficient signature check in the DxeImageVerificationHandler (bsc#1163969). - Enabled HTTPS-over-IPv6 (bsc#1153072).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for ovmf fixes the following issues: Security issues fixed: - CVE-2019-14563: Fixed a memory corruption caused by insufficient numeric truncation (bsc#1163959). - CVE-2019-14553: Fixed the TLS certification verification in HTTPS-over-IPv6 boot sequences (bsc#1153072). - CVE-2019-14559: Fixed a remotely exploitable memory leak in the ARP handling code (bsc#1163927). - CVE-2019-14575: Fixed an insufficient signature check in the DxeImageVerificationHandler (bsc#1163969). - Enabled HTTPS-over-IPv6 (bsc#1153072).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1153072
- https://bugzilla.suse.com/1163927
- https://bugzilla.suse.com/1163959
- https://bugzilla.suse.com/1163969
- https://www.suse.com/security/cve/CVE-2019-14553
- https://www.suse.com/security/cve/CVE-2019-14559
- https://www.suse.com/security/cve/CVE-2019-14563
- https://www.suse.com/security/cve/CVE-2019-14575
- https://www.suse.com/support/update/announcement/2020/suse-su-20200568-1/