shield
Security update for ovmf
SUSE-SLE-SAP-12-SP2-2020-495
This update for ovmf fixes the following issues: Security issues fixed: - CVE-2018-0739: Update openssl to 1.0.2o to limit ASN.1 constructed types recursive definition depth (bsc#1094291). - CVE-2019-14563: Fixed a memory corruption caused by insufficient numeric truncation (bsc#1163959). - CVE-2019-14559: Fixed a remotely exploitable memory leak in the ARP handling code (bsc#1163927). - CVE-2019-14575: Fixed an insufficient signature check in the DxeImageVerificationHandler (bsc#1163969). Bug fixes: - Only use SLES-UEFI-CA-Certificate-2048.crt for the SUSE flavor to provide the better compatibility. (bsc#1077330)
-
Release DateFeb 26 2020
-
ReferencesBugzilla: 1077330, 1094291, 1163927, 1163959, 1163969
CVEs: CVE-2018-0739, CVE-2019-14559, CVE-2019-14563, CVE-2019-14575 -
Typesecurity
-
Severitymoderate
cloud_download Downloads
SUSE Linux Enterprise Server for SAP Applications 12.2 x86_64
-
Packagesovmf
Open Virtual Machine Firmwareovmf-tools2015+git1462940744.321151f-19.10.3 lock rpm lock src
The BaseTools from edk2qemu-ovmf-x86_642015+git1462940744.321151f-19.10.3 lock rpm
Open Virtual Machine Firmware - QEMU rom images (x86_64)2015+git1462940744.321151f-19.10.3 lock rpm