Bug 1130496 - (CVE-2019-9923) VUL-1: CVE-2019-9923: tar: null-pointer dereference in pax_decode_header in sparse.c
(CVE-2019-9923)
VUL-1: CVE-2019-9923: tar: null-pointer dereference in pax_decode_header in s...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P4 - Low : Minor
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/226940/
CVSSv3:SUSE:CVE-2019-9923:3.3:(AV:L/A...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2019-03-26 09:31 UTC by Robert Frohl
Modified: 2022-05-05 19:17 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Robert Frohl 2019-03-26 09:39:52 UTC
tracking these codestreams as affected:
- SUSE:SLE-11:Update
- SUSE:SLE-12:Update
- SUSE:SLE-15:Update 

Not affected, because of missing code:
- SUSE:SLE-10-SP3:Update
Comment 2 Kristyna Streitova 2019-04-02 15:26:30 UTC
|    Codestream    |   Request    |
|------------------|--------------|
| SLE10SP3         | not affected |
| SLE11            | 188644       |
| SLE12            | 188643       |
| SLE15            | 188642       |
| openSUSE:Leap    | via SLE      |
| openSUSE:Factory | 688646       |

We are done here, I'm reassigning it back to the security team.
Comment 4 Swamp Workflow Management 2019-04-10 19:13:01 UTC
SUSE-SU-2019:0926-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1120610,1130496
CVE References: CVE-2018-20482,CVE-2019-9923
Sources used:
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src):    tar-1.30-3.3.2
SUSE Linux Enterprise Module for Basesystem 15 (src):    tar-1.30-3.3.2

*** NOTE: This information is not intended to be used for external
    communication, because this may only be a partial fix.
    If you have questions please reach out to maintenance coordination.
Comment 5 Swamp Workflow Management 2019-04-18 16:09:37 UTC
openSUSE-SU-2019:1237-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1120610,1130496
CVE References: CVE-2018-20482,CVE-2019-9923
Sources used:
openSUSE Leap 15.0 (src):    tar-1.30-lp150.7.1
Comment 7 Swamp Workflow Management 2019-11-11 20:11:16 UTC
SUSE-SU-2019:14215-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 1120610,1130496,1152736
CVE References: CVE-2018-20482,CVE-2019-9923
Sources used:
SUSE Linux Enterprise Server 11-SP4-LTSS (src):    tar-1.27.1-14.8.1
SUSE Linux Enterprise Point of Sale 11-SP3 (src):    tar-1.27.1-14.8.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    tar-1.27.1-14.8.1
SUSE Linux Enterprise Debuginfo 11-SP3 (src):    tar-1.27.1-14.8.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 8 Swamp Workflow Management 2020-09-30 16:13:55 UTC
SUSE-SU-2020:2806-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1120610,1130496
CVE References: CVE-2018-20482,CVE-2019-9923
JIRA References: 
Sources used:
SUSE Linux Enterprise Server 12-SP5 (src):    tar-1.27.1-15.6.3

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 9 Alexandros Toptsoglou 2020-10-21 15:51:53 UTC
Done
Comment 10 Swamp Workflow Management 2022-05-05 19:17:56 UTC
SUSE-SU-2022:1548-1: An update that solves three vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 1029961,1120610,1130496,1181131
CVE References: CVE-2018-20482,CVE-2019-9923,CVE-2021-20193
JIRA References: 
Sources used:
openSUSE Leap 15.3 (src):    tar-1.34-150000.3.12.1
SUSE Linux Enterprise Realtime Extension 15-SP2 (src):    tar-1.34-150000.3.12.1
SUSE Linux Enterprise Module for Basesystem 15-SP3 (src):    tar-1.34-150000.3.12.1
SUSE Linux Enterprise Micro 5.2 (src):    tar-1.34-150000.3.12.1
SUSE Linux Enterprise Micro 5.1 (src):    tar-1.34-150000.3.12.1
SUSE Linux Enterprise Micro 5.0 (src):    tar-1.34-150000.3.12.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.