Bugzilla – Full Text Bug Listing |
Summary: | VUL-1: CVE-2019-11059: u-boot: mishandling the ext4 64-bit extension, resulting in a buffer overflow | ||
---|---|---|---|
Product: | [Novell Products] SUSE Security Incidents | Reporter: | Robert Frohl <rfrohl> |
Component: | Incidents | Assignee: | Security Team bot <security-team> |
Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
Severity: | Minor | ||
Priority: | P4 - Low | CC: | afaerber, smash_bz |
Version: | unspecified | ||
Target Milestone: | --- | ||
Hardware: | Other | ||
OS: | Other | ||
URL: | https://smash.suse.de/issue/232535/ | ||
Whiteboard: | CVSSv3:SUSE:CVE-2019-11059:5.1:(AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L) maint:planned:update | ||
Found By: | Security Response Team | Services Priority: | |
Business Priority: | Blocker: | --- | |
Marketing QA Status: | --- | IT Deployment: | --- |
Description
Robert Frohl
2019-05-13 11:05:00 UTC
tracking all codestreams as affected: - SUSE:SLE-12-SP3:Update - SUSE:SLE-12-SP4:Update - SUSE:SLE-15:Update Concerning SUSE:SLE-12-SP3:Update: This might not be vulnerable if we go by the affected version, but the code looks like it could be vulnerable too. @Matthias: Please let us know if my assessment was incorrect and I can adjust our tracking. SUSE-SU-2020:3256-1: An update that fixes 20 vulnerabilities is now available. Category: security (important) Bug References: 1134157,1134853,1143463,1143777,1143817,1143818,1143819,1143820,1143821,1143823,1143824,1143825,1143827,1143828,1143830,1143831,1144656,1144675,1162198,1167209 CVE References: CVE-2019-11059,CVE-2019-11690,CVE-2019-13103,CVE-2019-13104,CVE-2019-13106,CVE-2019-14192,CVE-2019-14193,CVE-2019-14194,CVE-2019-14195,CVE-2019-14196,CVE-2019-14197,CVE-2019-14198,CVE-2019-14199,CVE-2019-14200,CVE-2019-14201,CVE-2019-14202,CVE-2019-14203,CVE-2019-14204,CVE-2020-10648,CVE-2020-8432 JIRA References: Sources used: SUSE Linux Enterprise Server 12-SP4-LTSS (src): u-boot-2018.03-4.3.1, u-boot-rpi3-2018.03-4.3.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. SUSE-SU-2020:3255-1: An update that solves 18 vulnerabilities and has one errata is now available. Category: security (important) Bug References: 1134157,1134853,1143463,1143777,1143817,1143818,1143819,1143820,1143821,1143823,1143824,1143825,1143827,1143828,1143830,1143831,1160566,1162198,1167209 CVE References: CVE-2019-11059,CVE-2019-11690,CVE-2019-13103,CVE-2019-14192,CVE-2019-14193,CVE-2019-14194,CVE-2019-14195,CVE-2019-14196,CVE-2019-14197,CVE-2019-14198,CVE-2019-14199,CVE-2019-14200,CVE-2019-14201,CVE-2019-14202,CVE-2019-14203,CVE-2019-14204,CVE-2020-10648,CVE-2020-8432 JIRA References: Sources used: SUSE Linux Enterprise Server 12-SP5 (src): u-boot-2019.01-5.3.1, u-boot-rpi3-2019.01-5.3.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. SUSE-SU-2020:3282-1: An update that fixes 18 vulnerabilities is now available. Category: security (important) Bug References: 1134157,1134853,1143463,1143777,1143817,1143818,1143819,1143820,1143821,1143823,1143824,1143825,1143827,1143828,1143830,1143831,1162198,1167209 CVE References: CVE-2019-11059,CVE-2019-11690,CVE-2019-13103,CVE-2019-14192,CVE-2019-14193,CVE-2019-14194,CVE-2019-14195,CVE-2019-14196,CVE-2019-14197,CVE-2019-14198,CVE-2019-14199,CVE-2019-14200,CVE-2019-14201,CVE-2019-14202,CVE-2019-14203,CVE-2019-14204,CVE-2020-10648,CVE-2020-8432 JIRA References: Sources used: SUSE Linux Enterprise Module for Basesystem 15-SP1 (src): u-boot-2019.01-7.10.1, u-boot-rpi3-2019.01-7.10.2 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. SUSE-SU-2020:3283-1: An update that solves 18 vulnerabilities and has two fixes is now available. Category: security (important) Bug References: 1098447,1098649,1134157,1134853,1143463,1143777,1143817,1143818,1143819,1143820,1143821,1143823,1143824,1143825,1143827,1143828,1143830,1143831,1162198,1167209 CVE References: CVE-2019-11059,CVE-2019-11690,CVE-2019-13103,CVE-2019-14192,CVE-2019-14193,CVE-2019-14194,CVE-2019-14195,CVE-2019-14196,CVE-2019-14197,CVE-2019-14198,CVE-2019-14199,CVE-2019-14200,CVE-2019-14201,CVE-2019-14202,CVE-2019-14203,CVE-2019-14204,CVE-2020-10648,CVE-2020-8432 JIRA References: Sources used: SUSE Linux Enterprise Server for SAP 15 (src): u-boot-2018.03-4.6.1 SUSE Linux Enterprise Server 15-LTSS (src): u-boot-2018.03-4.6.1, u-boot-rpi3-2018.03-4.6.2 SUSE Linux Enterprise High Performance Computing 15-LTSS (src): u-boot-2018.03-4.6.1, u-boot-rpi3-2018.03-4.6.2 SUSE Linux Enterprise High Performance Computing 15-ESPOS (src): u-boot-2018.03-4.6.1, u-boot-rpi3-2018.03-4.6.2 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. openSUSE-SU-2020:1930-1: An update that fixes 18 vulnerabilities is now available. Category: security (important) Bug References: 1134157,1134853,1143463,1143777,1143817,1143818,1143819,1143820,1143821,1143823,1143824,1143825,1143827,1143828,1143830,1143831,1162198,1167209 CVE References: CVE-2019-11059,CVE-2019-11690,CVE-2019-13103,CVE-2019-14192,CVE-2019-14193,CVE-2019-14194,CVE-2019-14195,CVE-2019-14196,CVE-2019-14197,CVE-2019-14198,CVE-2019-14199,CVE-2019-14200,CVE-2019-14201,CVE-2019-14202,CVE-2019-14203,CVE-2019-14204,CVE-2020-10648,CVE-2020-8432 JIRA References: Sources used: openSUSE Leap 15.1 (src): u-boot-2019.01-lp151.6.13.1 SUSE-SU-2020:3474-1: An update that fixes 17 vulnerabilities is now available. Category: security (important) Bug References: 1134157,1134853,1143463,1143777,1143817,1143818,1143819,1143820,1143821,1143823,1143824,1143825,1143827,1143828,1143830,1143831,1167209 CVE References: CVE-2019-11059,CVE-2019-11690,CVE-2019-13103,CVE-2019-14192,CVE-2019-14193,CVE-2019-14194,CVE-2019-14195,CVE-2019-14196,CVE-2019-14197,CVE-2019-14198,CVE-2019-14200,CVE-2019-14201,CVE-2019-14202,CVE-2019-14203,CVE-2019-14204,CVE-2019-14299,CVE-2020-10648 JIRA References: Sources used: SUSE Linux Enterprise Server 12-SP3-LTSS (src): u-boot-2016.07-12.3.1, u-boot-rpi3-2016.07-12.3.1 SUSE Enterprise Storage 5 (src): u-boot-2016.07-12.3.1, u-boot-rpi3-2016.07-12.3.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. DONE |