SUSE-SU-2016:2146-1

Source
https://www.suse.com/support/update/announcement/2016/suse-su-20162146-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2016:2146-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2016:2146-1
Related
Published
2016-08-24T11:55:12Z
Modified
2025-05-02T04:04:53.601354Z
Upstream
Summary
Security update for dosfstools
Details

dosfstools was updated to fix two security issues.

These security issues were fixed: - CVE-2015-8872: The setfat function in fat.c in dosfstools might have allowed attackers to corrupt a FAT12 filesystem or cause a denial of service (invalid memory read and crash) by writing an odd number of clusters to the third to last entry on a FAT12 filesystem, which triggers an 'off-by-two error (bsc#980364). - CVE-2016-4804: The readboot function in boot.c in dosfstools allowed attackers to cause a denial of service (crash) via a crafted filesystem, which triggers a heap-based buffer overflow in the (1) readfat function or an out-of-bounds heap read in (2) getfat function (bsc#980377).

References

Affected packages

SUSE:Linux Enterprise Server 11 SP4 / dosfstools

Package

Name
dosfstools
Purl
pkg:rpm/suse/dosfstools&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.26-3.1

Ecosystem specific

{
    "binaries": [
        {
            "dosfstools": "3.0.26-3.1"
        }
    ]
}

SUSE:Linux Enterprise Server for SAP Applications 11 SP4 / dosfstools

Package

Name
dosfstools
Purl
pkg:rpm/suse/dosfstools&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.26-3.1

Ecosystem specific

{
    "binaries": [
        {
            "dosfstools": "3.0.26-3.1"
        }
    ]
}