Bug 1159839 - (CVE-2019-20016) VUL-1: CVE-2019-20016: libmysofa: improper restriction of recursive function calls in readOHDRHeaderMessageDatatype in dataobject.c and directblockRead in fractalhead.c may lead to stack consumption
(CVE-2019-20016)
VUL-1: CVE-2019-20016: libmysofa: improper restriction of recursive function ...
Status: IN_PROGRESS
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.1
Other Other
: P4 - Low : Normal (vote)
: ---
Assigned To: Mia Herkt
Security Team bot
https://smash.suse.de/issue/249850/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2019-12-27 09:23 UTC by Alexandros Toptsoglou
Modified: 2021-03-22 02:17 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexandros Toptsoglou 2019-12-27 09:23:33 UTC
CVE-2019-20016

libmysofa 0.9 does not properly restrict recursive function calls, as
demonstrated by reports of stack consumption in readOHDRHeaderMessageDatatype in
dataobject.c and directblockRead in fractalhead.c.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-20016
https://github.com/hoene/libmysofa/commit/2e6fac6ab6156dae8e8c6f417741388084b70d6f
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20016
https://github.com/hoene/libmysofa/issues/84
https://github.com/hoene/libmysofa/issues/83
Comment 1 OBSbugzilla Bot 2021-03-08 13:40:30 UTC
This is an autogenerated message for OBS integration:
This bug (1159839) was mentioned in
https://build.opensuse.org/request/show/877733 Backports:SLE-15-SP3 / libmysofa
Comment 2 OBSbugzilla Bot 2021-03-14 20:40:28 UTC
This is an autogenerated message for OBS integration:
This bug (1159839) was mentioned in
https://build.opensuse.org/request/show/878980 15.2 / libmysofa
Comment 3 OBSbugzilla Bot 2021-03-15 01:30:29 UTC
This is an autogenerated message for OBS integration:
This bug (1159839) was mentioned in
https://build.opensuse.org/request/show/879015 15.2 / libmysofa
Comment 4 Swamp Workflow Management 2021-03-18 17:27:00 UTC
openSUSE-SU-2021:0444-1: An update that fixes 13 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1149919,1149920,1149922,1149924,1149926,1159839,1160040,1181977,1181978,1181979,1181980,1181981,1182883
CVE References: CVE-2019-16091,CVE-2019-16092,CVE-2019-16093,CVE-2019-16094,CVE-2019-16095,CVE-2019-20016,CVE-2019-20063,CVE-2020-36148,CVE-2020-36149,CVE-2020-36150,CVE-2020-36151,CVE-2020-36152,CVE-2020-6860
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    libmysofa-0.9.1-lp152.3.3.1
Comment 5 OBSbugzilla Bot 2021-03-20 18:40:06 UTC
This is an autogenerated message for OBS integration:
This bug (1159839) was mentioned in
https://build.opensuse.org/request/show/880270 Backports:SLE-15-SP3 / libmysofa
Comment 6 Swamp Workflow Management 2021-03-22 02:17:56 UTC
openSUSE-SU-2021:0459-1: An update that fixes 13 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1149919,1149920,1149922,1149924,1149926,1159839,1160040,1181977,1181978,1181979,1181980,1181981,1182883
CVE References: CVE-2019-16091,CVE-2019-16092,CVE-2019-16093,CVE-2019-16094,CVE-2019-16095,CVE-2019-20016,CVE-2019-20063,CVE-2020-36148,CVE-2020-36149,CVE-2020-36150,CVE-2020-36151,CVE-2020-36152,CVE-2020-6860
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP2 (src):    libmysofa-0.9.1-bp152.4.3.1