Bugzilla – Bug 1181977
VUL-1: CVE-2020-36152: libmysofa: Buffer overflow in readDataVar in hdf/dataobject.c
Last modified: 2021-03-22 02:18:10 UTC
CVE-2020-36152 Buffer overflow in readDataVar in hdf/dataobject.c in Symonics libmysofa 0.5 - 1.1 allows attackers to execute arbitrary code via a crafted SOFA. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-36152 https://github.com/hoene/libmysofa/issues/136 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36152
Fixed in 1.2: https://build.opensuse.org/request/show/876066
This is an autogenerated message for OBS integration: This bug (1181977) was mentioned in https://build.opensuse.org/request/show/877733 Backports:SLE-15-SP3 / libmysofa
This is an autogenerated message for OBS integration: This bug (1181977) was mentioned in https://build.opensuse.org/request/show/878980 15.2 / libmysofa
This is an autogenerated message for OBS integration: This bug (1181977) was mentioned in https://build.opensuse.org/request/show/879015 15.2 / libmysofa
openSUSE-SU-2021:0444-1: An update that fixes 13 vulnerabilities is now available. Category: security (moderate) Bug References: 1149919,1149920,1149922,1149924,1149926,1159839,1160040,1181977,1181978,1181979,1181980,1181981,1182883 CVE References: CVE-2019-16091,CVE-2019-16092,CVE-2019-16093,CVE-2019-16094,CVE-2019-16095,CVE-2019-20016,CVE-2019-20063,CVE-2020-36148,CVE-2020-36149,CVE-2020-36150,CVE-2020-36151,CVE-2020-36152,CVE-2020-6860 JIRA References: Sources used: openSUSE Leap 15.2 (src): libmysofa-0.9.1-lp152.3.3.1
This is an autogenerated message for OBS integration: This bug (1181977) was mentioned in https://build.opensuse.org/request/show/880270 Backports:SLE-15-SP3 / libmysofa
openSUSE-SU-2021:0459-1: An update that fixes 13 vulnerabilities is now available. Category: security (moderate) Bug References: 1149919,1149920,1149922,1149924,1149926,1159839,1160040,1181977,1181978,1181979,1181980,1181981,1182883 CVE References: CVE-2019-16091,CVE-2019-16092,CVE-2019-16093,CVE-2019-16094,CVE-2019-16095,CVE-2019-20016,CVE-2019-20063,CVE-2020-36148,CVE-2020-36149,CVE-2020-36150,CVE-2020-36151,CVE-2020-36152,CVE-2020-6860 JIRA References: Sources used: openSUSE Backports SLE-15-SP2 (src): libmysofa-0.9.1-bp152.4.3.1