SUSE SLES12 Security Update : transfig (SUSE-SU-2021:3124-1)

high Nessus Plugin ID 153462

Language:

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLES12 / SLES_SAP12 host has a package installed that is affected by multiple vulnerabilities as referenced in the SUSE-SU-2021:3124-1 advisory.

- read_textobject in read.c in Xfig fig2dev 3.2.7b has a stack-based buffer overflow because of an incorrect sscanf. (CVE-2019-19555)

- make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer overflow via a large arrow type. (CVE-2019-19746)

- read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write. (CVE-2019-19797)

- A stack-based buffer overflow in the put_arrow() component in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pict2e format.
(CVE-2020-21680)

- A global buffer overflow in the set_color component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into ge format. (CVE-2020-21681)

- A global buffer overflow in the set_fill component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into ge format. (CVE-2020-21682)

- A global buffer overflow in the shade_or_tint_name_after_declare_color in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pstricks format.
(CVE-2020-21683)

- An Out of Bounds flaw was found fig2dev version 3.2.8a. A flawed bounds check in read_objects() could allow an attacker to provide a crafted malicious input causing the application to either crash or in some cases cause memory corruption. The highest threat from this vulnerability is to integrity as well as system availability. (CVE-2021-3561)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected transfig package.

See Also

https://bugzilla.suse.com/1136882

https://bugzilla.suse.com/1159130

https://bugzilla.suse.com/1159293

https://bugzilla.suse.com/1161698

https://bugzilla.suse.com/1186329

https://bugzilla.suse.com/1189325

https://bugzilla.suse.com/1189343

https://bugzilla.suse.com/1189345

https://bugzilla.suse.com/1189346

https://www.suse.com/security/cve/CVE-2019-19555

https://www.suse.com/security/cve/CVE-2019-19746

https://www.suse.com/security/cve/CVE-2019-19797

https://www.suse.com/security/cve/CVE-2020-21680

https://www.suse.com/security/cve/CVE-2020-21681

https://www.suse.com/security/cve/CVE-2020-21682

https://www.suse.com/security/cve/CVE-2020-21683

https://www.suse.com/security/cve/CVE-2021-3561

http://www.nessus.org/u?550791ab

Plugin Details

Severity: High

ID: 153462

File Name: suse_SU-2021-3124-1.nasl

Version: 1.4

Type: local

Agent: unix

Published: 9/17/2021

Updated: 7/14/2023

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.0

CVSS v2

Risk Factor: Medium

Base Score: 5.8

Temporal Score: 4.5

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:P

CVSS Score Source: CVE-2021-3561

CVSS v3

Risk Factor: High

Base Score: 7.1

Temporal Score: 6.4

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:12, p-cpe:/a:novell:suse_linux:transfig

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/16/2021

Vulnerability Publication Date: 12/4/2019

Reference Information

CVE: CVE-2019-19555, CVE-2019-19746, CVE-2019-19797, CVE-2020-21680, CVE-2020-21681, CVE-2020-21682, CVE-2020-21683, CVE-2021-3561

SuSE: SUSE-SU-2021:3124-1