{"id":"openSUSE-SU-2019:1200-1","summary":"Security update for netpbm","details":"This update for netpbm fixes the following issues:\n\n- CVE-2018-8975: The pm_mallocarray2 function allowed remote attackers to cause\n  a denial of service (heap-based buffer over-read) via a crafted image file\n  (bsc#1086777).\n\nThis update was imported from the SUSE:SLE-15:Update update project.","modified":"2026-02-04T04:31:46.744411Z","published":"2019-04-12T12:54:48Z","related":["CVE-2018-8975"],"upstream":["CVE-2018-8975"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/I4AAN6P4XYXWQSGRZ2KBD6PS6OLL4LCL/#I4AAN6P4XYXWQSGRZ2KBD6PS6OLL4LCL"},{"type":"REPORT","url":"https://bugzilla.suse.com/1086777"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-8975"}],"affected":[{"package":{"name":"netpbm","ecosystem":"openSUSE:Leap 15.0","purl":"pkg:rpm/opensuse/netpbm&distro=openSUSE%20Leap%2015.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.80.1-lp150.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"libnetpbm11-32bit":"10.80.1-lp150.2.3.1","libnetpbm11":"10.80.1-lp150.2.3.1","netpbm":"10.80.1-lp150.2.3.1","libnetpbm-devel":"10.80.1-lp150.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2019:1200-1.json"}}],"schema_version":"1.7.3"}