{"affected":[{"ecosystem_specific":{"binaries":[{"libcdio++0":"0.94-6.3.1","libcdio-devel":"0.94-6.3.1","libcdio16":"0.94-6.3.1","libiso9660-10":"0.94-6.3.1","libudf0":"0.94-6.3.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Module for Desktop Applications 15","name":"libcdio","purl":"pkg:rpm/suse/libcdio&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"0.94-6.3.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for libcdio fixes the following issues:\n\nThe following security vulnerabilities were addressed:\n\n- CVE-2017-18199: Fixed a NULL pointer dereference in realloc_symlink in rock.c\n  (bsc#1082821)\n- CVE-2017-18201: Fixed a double free vulnerability in get_cdtext_generic() in\n  _cdio_generic.c (bsc#1082877)\n- Fixed several memory leaks (bsc#1082821)\n","id":"SUSE-SU-2018:2236-1","modified":"2018-08-07T10:48:04Z","published":"2018-08-07T10:48:04Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2018/suse-su-20182236-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1082821"},{"type":"REPORT","url":"https://bugzilla.suse.com/1082877"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-18199"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-18201"}],"related":["CVE-2017-18199","CVE-2017-18201"],"summary":"Security update for libcdio","upstream":["CVE-2017-18199","CVE-2017-18201"]}