Bugzilla – Full Text Bug Listing |
Summary: | VUL-0: CVE-2020-13999: libEMF: integer overflow and denial of service in ScaleViewPortExtEx | ||
---|---|---|---|
Product: | [Novell Products] SUSE Security Incidents | Reporter: | Robert Frohl <rfrohl> |
Component: | Incidents | Assignee: | Security Team bot <security-team> |
Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
Severity: | Minor | ||
Priority: | P3 - Medium | CC: | carlos.lopez, meissner, smash_bz |
Version: | unspecified | ||
Target Milestone: | --- | ||
Hardware: | Other | ||
OS: | Other | ||
URL: | https://smash.suse.de/issue/261541/ | ||
Whiteboard: | CVSSv3.1:SUSE:CVE-2020-13999:5.5:(AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H) | ||
Found By: | Security Response Team | Services Priority: | |
Business Priority: | Blocker: | --- | |
Marketing QA Status: | --- | IT Deployment: | --- |
Description
Robert Frohl
2020-06-17 12:31:10 UTC
relevant diff: https://sourceforge.net/p/libemf/code/98/tree//trunk/libemf/libemf.cpp?diff=50c6360b34309d09be9d1a1b:97 tracking both SUSE:SLE-12:Update and SUSE:SLE-15:Update as affected. maybe it makes sense to include the sanity check, that x_num, x_den, y_num, y_den are not 0, into the diff. Working on SUSE:SLE-12:Update and SUSE:SLE-15:Update Submitted: SUSE:SLE-12:Update : created request id 278469 SUSE:SLE-15:Update : created request id 278470 (In reply to Robert Frohl from comment #3) > maybe it makes sense to include the sanity check, that x_num, x_den, y_num, > y_den are not 0, into the diff. Yes, yes it does make sense. Resubmitted and superseded: SUSE:SLE-12:Update : created request id 278472 SUSE:SLE-15:Update : created request id 278471 My part is done, I think. Assigning to security-team. SUSE-SU-2022:3190-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1173070 CVE References: CVE-2020-13999 JIRA References: Sources used: SUSE Linux Enterprise Workstation Extension 12-SP5 (src): libEMF-1.0.7-11.6.1 SUSE Linux Enterprise Software Development Kit 12-SP5 (src): libEMF-1.0.7-11.6.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. SUSE-SU-2022:3191-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1173070 CVE References: CVE-2020-13999 JIRA References: Sources used: openSUSE Leap 15.3 (src): libEMF-1.0.7-150000.3.6.1 SUSE Linux Enterprise Workstation Extension 15-SP3 (src): libEMF-1.0.7-150000.3.6.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. done |