<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for opencv</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2018:1438-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2018-05-28T05:45:07Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2018-05-28T05:45:07Z</InitialReleaseDate>
    <CurrentReleaseDate>2018-05-28T05:45:07Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for opencv</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for opencv fixes the following issues:

- CVE-2018-5268: Fixed a heap-based buffer overflow in incv::Jpeg2KDecoder::readComponent8u in modules/imgcodecs/src/grfmt_jpeg2000.cppwhen parsing a crafted image file. (boo#1075017)
- CVE-2017-17760: Fixed an buffer overflow in function cv::PxMDecoder::readData (boo#1074313)
- CVE-2017-18009: Fixed a heap-based buffer over-read in function cv::HdrDecoder::checkSignature (boo#1074312)
- CVE-2017-1000450: Functions FillUniColor and FillUniGray do not check the input length which could lead to out of bounds writes and crashes (boo#1074487)
- CVE-2018-5269: Fixed an assertion failure happens in cv::RBaseStream::setPos inmodules/imgcodecs/src/bitstrm.cpp because of an incorrect integer cast (bsc#1075019).
  </Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00106.html</URL>
      <Description>E-Mail link for openSUSE-SU-2018:1438-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE Leap 42.3">
      <Branch Type="Product Name" Name="openSUSE Leap 42.3">
        <FullProductName ProductID="openSUSE Leap 42.3">openSUSE Leap 42.3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="libopencv-qt56_3-3.1.0-4.11.1">
      <FullProductName ProductID="libopencv-qt56_3-3.1.0-4.11.1">libopencv-qt56_3-3.1.0-4.11.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libopencv3_1-3.1.0-4.11.1">
      <FullProductName ProductID="libopencv3_1-3.1.0-4.11.1">libopencv3_1-3.1.0-4.11.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="opencv-3.1.0-4.11.1">
      <FullProductName ProductID="opencv-3.1.0-4.11.1">opencv-3.1.0-4.11.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="opencv-devel-3.1.0-4.11.1">
      <FullProductName ProductID="opencv-devel-3.1.0-4.11.1">opencv-devel-3.1.0-4.11.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="opencv-doc-3.1.0-4.11.1">
      <FullProductName ProductID="opencv-doc-3.1.0-4.11.1">opencv-doc-3.1.0-4.11.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="opencv-qt5-3.1.0-4.11.1">
      <FullProductName ProductID="opencv-qt5-3.1.0-4.11.1">opencv-qt5-3.1.0-4.11.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="opencv-qt5-devel-3.1.0-4.11.1">
      <FullProductName ProductID="opencv-qt5-devel-3.1.0-4.11.1">opencv-qt5-devel-3.1.0-4.11.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="opencv-qt5-doc-3.1.0-4.11.1">
      <FullProductName ProductID="opencv-qt5-doc-3.1.0-4.11.1">opencv-qt5-doc-3.1.0-4.11.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python-opencv-3.1.0-4.11.1">
      <FullProductName ProductID="python-opencv-3.1.0-4.11.1">python-opencv-3.1.0-4.11.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python-opencv-qt5-3.1.0-4.11.1">
      <FullProductName ProductID="python-opencv-qt5-3.1.0-4.11.1">python-opencv-qt5-3.1.0-4.11.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-opencv-3.1.0-4.11.1">
      <FullProductName ProductID="python3-opencv-3.1.0-4.11.1">python3-opencv-3.1.0-4.11.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-opencv-qt5-3.1.0-4.11.1">
      <FullProductName ProductID="python3-opencv-qt5-3.1.0-4.11.1">python3-opencv-qt5-3.1.0-4.11.1</FullProductName>
    </Branch>
    <Relationship ProductReference="libopencv-qt56_3-3.1.0-4.11.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:libopencv-qt56_3-3.1.0-4.11.1">libopencv-qt56_3-3.1.0-4.11.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libopencv3_1-3.1.0-4.11.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:libopencv3_1-3.1.0-4.11.1">libopencv3_1-3.1.0-4.11.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="opencv-3.1.0-4.11.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:opencv-3.1.0-4.11.1">opencv-3.1.0-4.11.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="opencv-devel-3.1.0-4.11.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:opencv-devel-3.1.0-4.11.1">opencv-devel-3.1.0-4.11.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="opencv-doc-3.1.0-4.11.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:opencv-doc-3.1.0-4.11.1">opencv-doc-3.1.0-4.11.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="opencv-qt5-3.1.0-4.11.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:opencv-qt5-3.1.0-4.11.1">opencv-qt5-3.1.0-4.11.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="opencv-qt5-devel-3.1.0-4.11.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:opencv-qt5-devel-3.1.0-4.11.1">opencv-qt5-devel-3.1.0-4.11.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="opencv-qt5-doc-3.1.0-4.11.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:opencv-qt5-doc-3.1.0-4.11.1">opencv-qt5-doc-3.1.0-4.11.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-opencv-3.1.0-4.11.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:python-opencv-3.1.0-4.11.1">python-opencv-3.1.0-4.11.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-opencv-qt5-3.1.0-4.11.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:python-opencv-qt5-3.1.0-4.11.1">python-opencv-qt5-3.1.0-4.11.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-opencv-3.1.0-4.11.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:python3-opencv-3.1.0-4.11.1">python3-opencv-3.1.0-4.11.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-opencv-qt5-3.1.0-4.11.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:python3-opencv-qt5-3.1.0-4.11.1">python3-opencv-qt5-3.1.0-4.11.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and FillUniGray do not check the input length, which can lead to integer overflow. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier.</Note>
    </Notes>
    <CVE>CVE-2017-1000450</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libopencv-qt56_3-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libopencv3_1-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:opencv-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:opencv-devel-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:opencv-doc-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:opencv-qt5-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:opencv-qt5-devel-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:opencv-qt5-doc-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:python-opencv-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:python-opencv-qt5-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:python3-opencv-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:python3-opencv-qt5-3.1.0-4.11.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00106.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-1000450.html</URL>
        <Description>CVE-2017-1000450</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1074487</URL>
        <Description>SUSE Bug 1074487</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">OpenCV 3.3.1 has a Buffer Overflow in the cv::PxMDecoder::readData function in grfmt_pxm.cpp, because an incorrect size value is used.</Note>
    </Notes>
    <CVE>CVE-2017-17760</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libopencv-qt56_3-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libopencv3_1-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:opencv-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:opencv-devel-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:opencv-doc-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:opencv-qt5-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:opencv-qt5-devel-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:opencv-qt5-doc-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:python-opencv-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:python-opencv-qt5-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:python3-opencv-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:python3-opencv-qt5-3.1.0-4.11.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00106.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-17760.html</URL>
        <Description>CVE-2017-17760</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1074313</URL>
        <Description>SUSE Bug 1074313</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In OpenCV 3.3.1, a heap-based buffer over-read exists in the function cv::HdrDecoder::checkSignature in modules/imgcodecs/src/grfmt_hdr.cpp.</Note>
    </Notes>
    <CVE>CVE-2017-18009</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libopencv-qt56_3-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libopencv3_1-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:opencv-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:opencv-devel-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:opencv-doc-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:opencv-qt5-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:opencv-qt5-devel-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:opencv-qt5-doc-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:python-opencv-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:python-opencv-qt5-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:python3-opencv-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:python3-opencv-qt5-3.1.0-4.11.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00106.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-18009.html</URL>
        <Description>CVE-2017-18009</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1074312</URL>
        <Description>SUSE Bug 1074312</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In OpenCV 3.3.1, a heap-based buffer overflow happens in cv::Jpeg2KDecoder::readComponent8u in modules/imgcodecs/src/grfmt_jpeg2000.cpp when parsing a crafted image file.</Note>
    </Notes>
    <CVE>CVE-2018-5268</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libopencv-qt56_3-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libopencv3_1-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:opencv-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:opencv-devel-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:opencv-doc-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:opencv-qt5-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:opencv-qt5-devel-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:opencv-qt5-doc-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:python-opencv-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:python-opencv-qt5-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:python3-opencv-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:python3-opencv-qt5-3.1.0-4.11.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00106.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-5268.html</URL>
        <Description>CVE-2018-5268</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1075017</URL>
        <Description>SUSE Bug 1075017</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In OpenCV 3.3.1, an assertion failure happens in cv::RBaseStream::setPos in modules/imgcodecs/src/bitstrm.cpp because of an incorrect integer cast.</Note>
    </Notes>
    <CVE>CVE-2018-5269</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libopencv-qt56_3-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libopencv3_1-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:opencv-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:opencv-devel-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:opencv-doc-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:opencv-qt5-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:opencv-qt5-devel-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:opencv-qt5-doc-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:python-opencv-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:python-opencv-qt5-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:python3-opencv-3.1.0-4.11.1</ProductID>
        <ProductID>openSUSE Leap 42.3:python3-opencv-qt5-3.1.0-4.11.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00106.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-5269.html</URL>
        <Description>CVE-2018-5269</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1075019</URL>
        <Description>SUSE Bug 1075019</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
