[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

252097

 
 

909

 
 

196747

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2022:2064-1 -- SLES grub2

ID: oval:org.secpod.oval:def:89047563Date: (C)2022-11-04   (M)2024-05-09
Class: PATCHFamily: unix




This update for grub2 fixes the following issues: Security fixes and hardenings for boothole 3 / boothole 2022 - CVE-2021-3695: Fixed that a crafted PNG grayscale image could lead to out-of-bounds write in heap - CVE-2021-3696: Fixed that a crafted PNG image could lead to out-of-bound write during huffman table handling - CVE-2021-3697: Fixed that a crafted JPEG image could lead to buffer underflow write in the heap - CVE-2022-28733: Fixed fragmentation math in net/ip - CVE-2022-28734: Fixed an out-of-bound write for split http headers - CVE-2022-28735: Fixed some verifier framework changes - CVE-2022-28736: Fixed a use-after-free in chainloader command - Update SBAT security contact - Bump grub"s SBAT generation to 2 - Use boot disks in OpenFirmware, fixing regression caused when the root LV is completely in the boot LUN

Platform:
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Desktop 15 SP3
Product:
grub2
Reference:
SUSE-SU-2022:2064-1
CVE-2021-3695
CVE-2021-3696
CVE-2021-3697
CVE-2022-28733
CVE-2022-28734
CVE-2022-28735
CVE-2022-28736
CVE    7
CVE-2021-3697
CVE-2021-3695
CVE-2021-3696
CVE-2022-28733
...
CPE    3
cpe:/a:gnu:grub2
cpe:/o:suse:suse_linux_enterprise_server:15:sp3
cpe:/o:suse:suse_linux_enterprise_desktop:15:sp3

© SecPod Technologies