Bugzilla – Full Text Bug Listing |
Summary: | VUL-0: CVE-2018-10536: wavpack: The WAV parser componentcontains a vulnerability that allows writing to memory becauseParseRiffHeaderConfig in riff.c does not reject multiple format chunks. | ||
---|---|---|---|
Product: | [Novell Products] SUSE Security Incidents | Reporter: | Alexander Bergmann <abergmann> |
Component: | Incidents | Assignee: | Security Team bot <security-team> |
Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
Severity: | Normal | ||
Priority: | P3 - Medium | CC: | abergmann, atoptsoglou, simonalogan, smash_bz |
Version: | unspecified | ||
Target Milestone: | --- | ||
Hardware: | Other | ||
OS: | Other | ||
URL: | https://smash.suse.de/issue/205022/ | ||
Whiteboard: | CVSSv3.1:SUSE:CVE-2018-10536:7.8:(AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) | ||
Found By: | Security Response Team | Services Priority: | |
Business Priority: | Blocker: | --- | |
Marketing QA Status: | --- | IT Deployment: | --- |
Description
Alexander Bergmann
2018-04-30 08:48:40 UTC
Relevant function was introduced in version 5.0.0. Therefore SLE and openSUSE are not affected. Closing. SLE15 is affected Leap 15.2 is also affected. Do you plan to fix Leap 15.2? (In reply to Simon Logan from comment #4) > Leap 15.2 is also affected. Do you plan to fix Leap 15.2? Hi Simon, Leap 15.2 package is inherited from SLE-15-SP2 (that is the codestream SLE15 that I mention in comment 2). I attempted to bring it to the latest version, in case this passes testing with no issues this will rrive to Leap as well Thanks Alexandros. SUSE-SU-2021:0186-1: An update that fixes 13 vulnerabilities is now available. Category: security (moderate) Bug References: 1091340,1091341,1091342,1091343,1091344,1180414 CVE References: CVE-2018-10536,CVE-2018-10537,CVE-2018-10538,CVE-2018-10539,CVE-2018-10540,CVE-2018-19840,CVE-2018-19841,CVE-2018-6767,CVE-2018-7253,CVE-2018-7254,CVE-2019-1010319,CVE-2019-11498,CVE-2020-35738 JIRA References: Sources used: SUSE Manager Server 4.0 (src): wavpack-5.4.0-4.9.1 SUSE Manager Retail Branch Server 4.0 (src): wavpack-5.4.0-4.9.1 SUSE Manager Proxy 4.0 (src): wavpack-5.4.0-4.9.1 SUSE Linux Enterprise Server for SAP 15-SP1 (src): wavpack-5.4.0-4.9.1 SUSE Linux Enterprise Server for SAP 15 (src): wavpack-5.4.0-4.9.1 SUSE Linux Enterprise Server 15-SP1-LTSS (src): wavpack-5.4.0-4.9.1 SUSE Linux Enterprise Server 15-SP1-BCL (src): wavpack-5.4.0-4.9.1 SUSE Linux Enterprise Server 15-LTSS (src): wavpack-5.4.0-4.9.1 SUSE Linux Enterprise Module for Desktop Applications 15-SP3 (src): wavpack-5.4.0-4.9.1 SUSE Linux Enterprise Module for Desktop Applications 15-SP2 (src): wavpack-5.4.0-4.9.1 SUSE Linux Enterprise Module for Basesystem 15-SP3 (src): wavpack-5.4.0-4.9.1 SUSE Linux Enterprise Module for Basesystem 15-SP2 (src): wavpack-5.4.0-4.9.1 SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src): wavpack-5.4.0-4.9.1 SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src): wavpack-5.4.0-4.9.1 SUSE Linux Enterprise High Performance Computing 15-LTSS (src): wavpack-5.4.0-4.9.1 SUSE Linux Enterprise High Performance Computing 15-ESPOS (src): wavpack-5.4.0-4.9.1 SUSE Enterprise Storage 6 (src): wavpack-5.4.0-4.9.1 SUSE CaaS Platform 4.0 (src): wavpack-5.4.0-4.9.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. openSUSE-SU-2021:0153-1: An update that fixes 13 vulnerabilities is now available. Category: security (moderate) Bug References: 1091340,1091341,1091342,1091343,1091344,1180414 CVE References: CVE-2018-10536,CVE-2018-10537,CVE-2018-10538,CVE-2018-10539,CVE-2018-10540,CVE-2018-19840,CVE-2018-19841,CVE-2018-6767,CVE-2018-7253,CVE-2018-7254,CVE-2019-1010319,CVE-2019-11498,CVE-2020-35738 JIRA References: Sources used: openSUSE Leap 15.2 (src): wavpack-5.4.0-lp152.7.3.1 openSUSE-SU-2021:0154-1: An update that fixes 13 vulnerabilities is now available. Category: security (moderate) Bug References: 1091340,1091341,1091342,1091343,1091344,1180414 CVE References: CVE-2018-10536,CVE-2018-10537,CVE-2018-10538,CVE-2018-10539,CVE-2018-10540,CVE-2018-19840,CVE-2018-19841,CVE-2018-6767,CVE-2018-7253,CVE-2018-7254,CVE-2019-1010319,CVE-2019-11498,CVE-2020-35738 JIRA References: Sources used: openSUSE Leap 15.1 (src): wavpack-5.4.0-lp151.5.6.1 Done |