{"affected":[{"ecosystem_specific":{"binaries":[{"libnetpbm11":"10.80.1-3.3.36","netpbm":"10.80.1-3.3.36"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15","name":"netpbm","purl":"pkg:rpm/suse/netpbm&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"10.80.1-3.3.36"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libnetpbm-devel":"10.80.1-3.3.36"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Module for Desktop Applications 15","name":"netpbm","purl":"pkg:rpm/suse/netpbm&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"10.80.1-3.3.36"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for netpbm fixes the following issues:\n\n- CVE-2018-8975: The pm_mallocarray2 function allowed remote attackers to cause\n  a denial of service (heap-based buffer over-read) via a crafted image file\n  (bsc#1086777).\n","id":"SUSE-SU-2019:0855-1","modified":"2019-04-03T09:50:03Z","published":"2019-04-03T09:50:03Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2019/suse-su-20190855-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1086777"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-8975"}],"related":["CVE-2018-8975"],"summary":"Security update for netpbm","upstream":["CVE-2018-8975"]}