Bugzilla – Bug 1082776
VUL-0: CVE-2018-7437: freexl: heap-buffer-overflow in freexl.c:1866 parse_SST
Last modified: 2018-03-01 15:37:38 UTC
rh#1547885 An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a memcpy call of the parse_SST function. References: https://bugzilla.redhat.com/show_bug.cgi?id=1547885 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-7437 http://www.cvedetails.com/cve/CVE-2018-7437/
This is an autogenerated message for OBS integration: This bug (1082776) was mentioned in https://build.opensuse.org/request/show/580161 42.3 / freexl https://build.opensuse.org/request/show/580163 Backports:SLE-12 / freexl
done
openSUSE-SU-2018:0569-1: An update that fixes 5 vulnerabilities is now available. Category: security (important) Bug References: 1082774,1082775,1082776,1082777,1082778 CVE References: CVE-2018-7435,CVE-2018-7436,CVE-2018-7437,CVE-2018-7438,CVE-2018-7439 Sources used: SUSE Package Hub for SUSE Linux Enterprise 12 (src): freexl-1.0.5-8.1
openSUSE-SU-2018:0570-1: An update that fixes 5 vulnerabilities is now available. Category: security (important) Bug References: 1082774,1082775,1082776,1082777,1082778 CVE References: CVE-2018-7435,CVE-2018-7436,CVE-2018-7437,CVE-2018-7438,CVE-2018-7439 Sources used: openSUSE Leap 42.3 (src): freexl-1.0.5-8.1