{"id":"openSUSE-SU-2019:2033-1","summary":"Security update for libmirage","details":"This update for libmirage fixes the following issues:\n\nCVE-2019-15540: The CSO filter in libMirage in CDemu did not validate the part size,\ntriggering a heap-based buffer overflow that could lead to root access by a local user.\n[boo#1148087]\n\n- Update to new upstream release 3.2.2\n  * ISO parser: fixed ISO9660/UDF pattern search for sector\n    sizes 2332 and 2336.\n  * ISO parser: added support for Nintendo GameCube and Wii\n    ISO images.\n  * Extended medium type guess to distinguish between DVD and\n    BluRay images based on length.\n  * Removed fabrication of disc structures from the library\n    (moved to CDEmu daemon).\n  * MDS parser: cleanup of disc structure parsing, fixed the\n    incorrectly set structure sizes.\n","modified":"2026-02-04T03:36:56.799153Z","published":"2019-08-31T14:21:27Z","related":["CVE-2019-15540"],"upstream":["CVE-2019-15540"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/AUXYDY763KIJOAZ4TN3KVXUOAF2N6LCY/#AUXYDY763KIJOAZ4TN3KVXUOAF2N6LCY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1148087"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-15540"}],"affected":[{"package":{"name":"libmirage","ecosystem":"openSUSE:Leap 15.1","purl":"pkg:rpm/opensuse/libmirage&distro=openSUSE%20Leap%2015.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.2.2-lp151.3.3.1"}]}],"ecosystem_specific":{"binaries":[{"libmirage-3_2":"3.2.2-lp151.3.3.1","libmirage-data":"3.2.2-lp151.3.3.1","libmirage-devel":"3.2.2-lp151.3.3.1","libmirage-lang":"3.2.2-lp151.3.3.1","libmirage11":"3.2.2-lp151.3.3.1","typelib-1_0-libmirage-3_2":"3.2.2-lp151.3.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2019:2033-1.json"}}],"schema_version":"1.7.3"}