[SUSE-SU-2016:0779-1] Security update for graphite2

Severity Important
Affected Packages 14
CVEs 3

Security update for graphite2

This update for graphite2 fixes the following issues:

  • CVE-2016-1521: The directrun function in directmachine.cpp in
    Libgraphite did not validate a certain skip operation, which allowed
    remote attackers to execute arbitrary code, obtain sensitive information,
    or cause a denial of service (out-of-bounds read and application crash)
    via a crafted Graphite smart font.

  • CVE-2016-1523: The SillMap::readFace function in FeatureMap.cpp in
    Libgraphite mishandled a return value, which allowed remote attackers
    to cause a denial of service (missing initialization, NULL pointer
    dereference, and application crash) via a crafted Graphite smart font.

  • CVE-2016-1526: The TtfUtil:LocaLookup function in TtfUtil.cpp in
    Libgraphite incorrectly validated a size value, which allowed remote
    attackers to obtain sensitive information or cause a denial of service
    (out-of-bounds read and application crash) via a crafted Graphite
    smart font.

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/suse/libgraphite2-3?arch=x86_64&distro=sles-12&sp=1 suse libgraphite2-3 < 1.3.1-6.1 sles-12 x86_64
Affected pkg:rpm/suse/libgraphite2-3?arch=x86_64&distro=sles-12 suse libgraphite2-3 < 1.3.1-6.1 sles-12 x86_64
Affected pkg:rpm/suse/libgraphite2-3?arch=x86_64&distro=sled-12&sp=1 suse libgraphite2-3 < 1.3.1-6.1 sled-12 x86_64
Affected pkg:rpm/suse/libgraphite2-3?arch=x86_64&distro=sled-12 suse libgraphite2-3 < 1.3.1-6.1 sled-12 x86_64
Affected pkg:rpm/suse/libgraphite2-3?arch=s390x&distro=sles-12&sp=1 suse libgraphite2-3 < 1.3.1-6.1 sles-12 s390x
Affected pkg:rpm/suse/libgraphite2-3?arch=s390x&distro=sles-12 suse libgraphite2-3 < 1.3.1-6.1 sles-12 s390x
Affected pkg:rpm/suse/libgraphite2-3?arch=ppc64le&distro=sles-12&sp=1 suse libgraphite2-3 < 1.3.1-6.1 sles-12 ppc64le
Affected pkg:rpm/suse/libgraphite2-3?arch=ppc64le&distro=sles-12 suse libgraphite2-3 < 1.3.1-6.1 sles-12 ppc64le
Affected pkg:rpm/suse/libgraphite2-3-32bit?arch=x86_64&distro=sles-12&sp=1 suse libgraphite2-3-32bit < 1.3.1-6.1 sles-12 x86_64
Affected pkg:rpm/suse/libgraphite2-3-32bit?arch=x86_64&distro=sles-12 suse libgraphite2-3-32bit < 1.3.1-6.1 sles-12 x86_64
Affected pkg:rpm/suse/libgraphite2-3-32bit?arch=x86_64&distro=sled-12&sp=1 suse libgraphite2-3-32bit < 1.3.1-6.1 sled-12 x86_64
Affected pkg:rpm/suse/libgraphite2-3-32bit?arch=x86_64&distro=sled-12 suse libgraphite2-3-32bit < 1.3.1-6.1 sled-12 x86_64
Affected pkg:rpm/suse/libgraphite2-3-32bit?arch=s390x&distro=sles-12&sp=1 suse libgraphite2-3-32bit < 1.3.1-6.1 sles-12 s390x
Affected pkg:rpm/suse/libgraphite2-3-32bit?arch=s390x&distro=sles-12 suse libgraphite2-3-32bit < 1.3.1-6.1 sles-12 s390x
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...