SUSE-SU-2019:0839-1

Advisory lineage Upstream: 4 Downstream: 0
Published: 02 Apr 2019, 11:13
Last modified:04 Feb 2026, 03:02

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

02 Apr 2019, 11:13
Published
Vulnerability first disclosed
04 Feb 2026, 03:02
Last Modified
Vulnerability information updated

Description

Security update for file This update for file fixes the following issues: The following security vulnerabilities were addressed: - Fixed an out-of-bounds read in the function do_core_note in readelf.c, which allowed remote attackers to cause a denial of service (application crash) via a crafted ELF file (bsc#1096974 CVE-2018-10360). - CVE-2019-8905: Fixed a stack-based buffer over-read in do_core_note in readelf.c (bsc#1126118) - CVE-2019-8906: Fixed an out-of-bounds read in do_core_note in readelf. c (bsc#1126119) - CVE-2019-8907: Fixed a stack corruption in do_core_note in readelf.c (bsc#1126117)

Affected Systems

  • susefile&distro=SUSE Linux Enterprise Desktop 12 SP3

    < 5.22-10.12.2

  • susefile&distro=SUSE Linux Enterprise Desktop 12 SP4

    < 5.22-10.12.2

  • susefile&distro=SUSE Linux Enterprise Server 12 SP3

    < 5.22-10.12.2

  • susefile&distro=SUSE Linux Enterprise Server 12 SP4

    < 5.22-10.12.2

  • susefile&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP3

    < 5.22-10.12.2

  • susefile&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP4

    < 5.22-10.12.2

  • susefile&distro=SUSE Linux Enterprise Software Development Kit 12 SP3

    < 5.22-10.12.2

  • susefile&distro=SUSE Linux Enterprise Software Development Kit 12 SP4

    < 5.22-10.12.2

  • susepython-magic&distro=SUSE Linux Enterprise Software Development Kit 12 SP3

    < 5.22-10.12.2

  • susepython-magic&distro=SUSE Linux Enterprise Software Development Kit 12 SP4

    < 5.22-10.12.2

References (10)