Sign Up
Log In
Log In
or
Sign Up
Places
All Projects
Status Monitor
Collapse sidebar
SUSE:SLE-12-SP4:Update
patchinfo.2621
_patchinfo
Overview
Repositories
Revisions
Requests
Users
Attributes
Meta
File _patchinfo of Package patchinfo.2621
<patchinfo incident="2621"> <issue id="912607" tracker="bnc">fsck.fat 3.0.26 (2014-03-07): "/ Bad short file name ()."</issue> <issue id="980364" tracker="bnc">VUL-0: CVE-2015-8872: dosfstools: Off-by-2 error leading to corruption in FAT12</issue> <issue id="980377" tracker="bnc">VUL-1: CVE-2016-4804: dosfstools: Heap-buffer-overflows in read_fat() and get_fat() functions</issue> <issue id="2015-8872" tracker="cve" /> <issue id="2016-4804" tracker="cve" /> <category>security</category> <rating>moderate</rating> <packager>matejcik</packager> <name>dosfstools</name> <description>dosfstools was updated to fix two security issues. These security issues were fixed: - CVE-2015-8872: The set_fat function in fat.c in dosfstools might have allowed attackers to corrupt a FAT12 filesystem or cause a denial of service (invalid memory read and crash) by writing an odd number of clusters to the third to last entry on a FAT12 filesystem, which triggers an "off-by-two error (bsc#980364). - CVE-2016-4804: The read_boot function in boot.c in dosfstools allowed attackers to cause a denial of service (crash) via a crafted filesystem, which triggers a heap-based buffer overflow in the (1) read_fat function or an out-of-bounds heap read in (2) get_fat function (bsc#980377). This non-security issue was fixed: - bsc#912607: Attempt to rename root dir in fsck due to uninitialized fields. </description> <summary>Security update for dosfstools</summary> </patchinfo>
Locations
Projects
Search
Status Monitor
Help
OpenBuildService.org
Documentation
API Documentation
Code of Conduct
Contact
Support
@OBShq
Terms
openSUSE Build Service is sponsored by
The Open Build Service is an
openSUSE project
.
Sign Up
Log In
Places
Places
All Projects
Status Monitor