File _patchinfo of Package patchinfo.316

<patchinfo incident="316">
  <issue id="908742" tracker="bnc">Failure with mkfs.minix</issue>
  <issue id="907434" tracker="bnc">CVE-2014-9114: util-linux: command injection flaw in blkid</issue>
  <issue id="CVE-2014-9114" tracker="cve" />
  <category>security</category>
  <rating>moderate</rating>
  <packager>sbrabec</packager>
  <description>util-linux was updated to fix one security issue.

This security issue was fixed:
- CVE-2014-9114: Using crafted block devices (e.g. USB sticks) it was possibly to inject code via libblkid.
  libblkid was fixed to care about unsafe chars and possible buffer overflow in cache (bnc#907434)

This non-security issue was fixed:
- libblkid: Reset errno in blkid_probe_get_buffer() to prevent
  failing probes (e. g. for exFAT) (bnc#908742).
</description>
  <summary>Security update for util-linux</summary>
</patchinfo>
openSUSE Build Service is sponsored by