Bugzilla – Bug 1197028
VUL-0: CVE-2022-0856: libcaca: divide by zero issue via img2txt
Last modified: 2022-05-03 19:19:11 UTC
CVE-2022-0856 libcaca is affected by a Divide By Zero issue via img2txt, which allows a remote malicious user to cause a Denial of Service References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-0856 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0856 https://github.com/cacalabs/libcaca/issues/65
No fix has been provided upstream. The following should be affected: - SUSE:SLE-11:Update - SUSE:SLE-12:Update - SUSE:SLE-15:Update - SUSE:SLE-15-SP2:Update - openSUSE:Factory
SUSE:SLE-11:Update - https://build.suse.de/request/show/270952 SUSE:SLE-12:Update - https://build.suse.de/request/show/270954 SUSE:SLE-15:Update - https://build.suse.de/request/show/270956 SUSE:SLE-15-SP2:Update - https://build.suse.de/request/show/270957 openSUSE:Factory - https://build.opensuse.org/request/show/973060 Note that the patch has not yet been accepted upstream.
SUSE-SU-2022:1476-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1197028 CVE References: CVE-2022-0856 JIRA References: Sources used: openSUSE Leap 15.4 (src): libcaca-0.99.beta19.git20171003-150200.11.6.1 openSUSE Leap 15.3 (src): libcaca-0.99.beta19.git20171003-150200.11.6.1 SUSE Linux Enterprise Realtime Extension 15-SP2 (src): libcaca-0.99.beta19.git20171003-150200.11.6.1 SUSE Linux Enterprise Module for Basesystem 15-SP4 (src): libcaca-0.99.beta19.git20171003-150200.11.6.1 SUSE Linux Enterprise Module for Basesystem 15-SP3 (src): libcaca-0.99.beta19.git20171003-150200.11.6.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2022:1508-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1197028 CVE References: CVE-2022-0856 JIRA References: Sources used: SUSE Linux Enterprise Software Development Kit 12-SP5 (src): libcaca-0.99.beta18-14.9.1 SUSE Linux Enterprise Server 12-SP5 (src): libcaca-0.99.beta18-14.9.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.