SUSE-SU-2017:1938-1

Source
https://www.suse.com/support/update/announcement/2017/suse-su-20171938-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2017:1938-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2017:1938-1
Upstream
  • CVE-2015-1338
Related
  • CVE-2015-1338
Published
2017-07-24T13:37:26Z
Modified
2026-02-04T03:31:42Z
Summary
Security update for apport
Details

This update for apport fixes the following issues:

Security issue fixed:

  • CVE-2015-1338: Insecurely created crash dumps could lead to a DoS or privilege escalation through malicious symlinks. (bsc#947731)
References

Affected packages

SUSE:Linux Enterprise Server 11 SP4
apport

Package

Name
apport
Purl
pkg:rpm/suse/apport&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.114-12.8.3.1

Ecosystem specific

{
    "binaries": [
        {
            "apport": "0.114-12.8.3.1",
            "apport-crashdb-sle": "0.114-0.8.3.1",
            "apport-gtk": "0.114-12.8.3.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2017:1938-1.json"
apport-crashdb-sle

Package

Name
apport-crashdb-sle
Purl
pkg:rpm/suse/apport-crashdb-sle&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.114-0.8.3.1

Ecosystem specific

{
    "binaries": [
        {
            "apport": "0.114-12.8.3.1",
            "apport-crashdb-sle": "0.114-0.8.3.1",
            "apport-gtk": "0.114-12.8.3.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2017:1938-1.json"
SUSE:Linux Enterprise Server for SAP Applications 11 SP4
apport

Package

Name
apport
Purl
pkg:rpm/suse/apport&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.114-12.8.3.1

Ecosystem specific

{
    "binaries": [
        {
            "apport": "0.114-12.8.3.1",
            "apport-crashdb-sle": "0.114-0.8.3.1",
            "apport-gtk": "0.114-12.8.3.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2017:1938-1.json"
apport-crashdb-sle

Package

Name
apport-crashdb-sle
Purl
pkg:rpm/suse/apport-crashdb-sle&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.114-0.8.3.1

Ecosystem specific

{
    "binaries": [
        {
            "apport": "0.114-12.8.3.1",
            "apport-crashdb-sle": "0.114-0.8.3.1",
            "apport-gtk": "0.114-12.8.3.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2017:1938-1.json"