Overview

Request 953226 accepted

- security update
- added patches
fix CVE-2021-40985 [bsc#1192357], buffer overflow may lead to DoS via a crafted BMP image
+ htmldoc.openSUSE_Backports_SLE-12-SP1-CVE-2021-40985.patch
fix CVE-2021-43579 [bsc#1194487], stack-based buffer overflow in image_load_bmp() results in remote code execution if the victim converts an HTML document linking to a crafted BMP file
+ htmldoc.openSUSE_Backports_SLE-12-SP1-CVE-2021-43579.patch
fix CVE-2022-0534 [bsc#1195758], stack out-of-bounds read in gif_get_code() when opening a malicious GIF file results in a segmentation fault
+ htmldoc.openSUSE_Backports_SLE-12-SP1-CVE-2022-0534.patch

Request History
Petr Gajdos's avatar

pgajdos created request

- security update
- added patches
fix CVE-2021-40985 [bsc#1192357], buffer overflow may lead to DoS via a crafted BMP image
+ htmldoc.openSUSE_Backports_SLE-12-SP1-CVE-2021-40985.patch
fix CVE-2021-43579 [bsc#1194487], stack-based buffer overflow in image_load_bmp() results in remote code execution if the victim converts an HTML document linking to a crafted BMP file
+ htmldoc.openSUSE_Backports_SLE-12-SP1-CVE-2021-43579.patch
fix CVE-2022-0534 [bsc#1195758], stack out-of-bounds read in gif_get_code() when opening a malicious GIF file results in a segmentation fault
+ htmldoc.openSUSE_Backports_SLE-12-SP1-CVE-2022-0534.patch


Maintenance Bot's avatar

maintbot added factory-source as a reviewer


Maintenance Bot's avatar

maintbot added Publishing as a reviewer

Submission for None by someone who is not maintainer in the devel project (Publishing). Please review


Maintenance Bot's avatar

maintbot accepted review

ok


Factory Auto's avatar

factory-auto accepted review

Check script succeeded


Marcus Meissner's avatar

msmeissn accepted request

ok

openSUSE Build Service is sponsored by