Bug 1182883 (CVE-2020-6860)

Summary: VUL-1: CVE-2020-6860: libmysofa: stack-based buffer overflow in readDataVar
Product: [openSUSE] openSUSE Distribution Reporter: Andreas Stieger <Andreas.Stieger>
Component: SecurityAssignee: Mia Herkt <mia>
Status: IN_PROGRESS --- QA Contact: E-mail List <qa-bugs>
Severity: Normal    
Priority: P4 - Low CC: mia, security-team
Version: Leap 15.2   
Target Milestone: ---   
Hardware: Other   
OS: Other   
Whiteboard:
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Andreas Stieger 2021-03-01 22:22:54 UTC
libmysofa 0.9.1 has a stack-based buffer overflow in readDataVar in hdf/dataobject.c during the reading of a header message attribute. 

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6860
MISC:https://github.com/hoene/libmysofa/issues/96
Comment 1 OBSbugzilla Bot 2021-03-15 01:30:59 UTC
This is an autogenerated message for OBS integration:
This bug (1182883) was mentioned in
https://build.opensuse.org/request/show/879015 15.2 / libmysofa
Comment 2 Swamp Workflow Management 2021-03-18 17:27:53 UTC
openSUSE-SU-2021:0444-1: An update that fixes 13 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1149919,1149920,1149922,1149924,1149926,1159839,1160040,1181977,1181978,1181979,1181980,1181981,1182883
CVE References: CVE-2019-16091,CVE-2019-16092,CVE-2019-16093,CVE-2019-16094,CVE-2019-16095,CVE-2019-20016,CVE-2019-20063,CVE-2020-36148,CVE-2020-36149,CVE-2020-36150,CVE-2020-36151,CVE-2020-36152,CVE-2020-6860
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    libmysofa-0.9.1-lp152.3.3.1