{"affected":[{"ecosystem_specific":{"binaries":[{"tcmu-runner":"1.0.4-3.3.10"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for Raspberry Pi 12 SP2","name":"tcmu-runner","purl":"pkg:rpm/suse/tcmu-runner&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.0.4-3.3.10"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"tcmu-runner-devel":"1.0.4-3.3.10"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP2","name":"tcmu-runner","purl":"pkg:rpm/suse/tcmu-runner&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.0.4-3.3.10"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"tcmu-runner":"1.0.4-3.3.10"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP2","name":"tcmu-runner","purl":"pkg:rpm/suse/tcmu-runner&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.0.4-3.3.10"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"tcmu-runner":"1.0.4-3.3.10"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP2","name":"tcmu-runner","purl":"pkg:rpm/suse/tcmu-runner&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.0.4-3.3.10"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for tcmu-runner fixes the following issues:\n\nSecurity issues fixed:\n\n- CVE-2017-1000198: The glfs handler allowed local DoS via crafted CheckConfig strings (bsc#1049485)\n- CVE-2017-1000199: The qcow handler leaked information via the CheckConfig D-Bus method (bsc#1049491)\n","id":"SUSE-SU-2017:2601-1","modified":"2017-09-29T12:45:48Z","published":"2017-09-29T12:45:48Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2017/suse-su-20172601-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1049485"},{"type":"REPORT","url":"https://bugzilla.suse.com/1049491"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-1000198"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-1000199"}],"related":["CVE-2017-1000198","CVE-2017-1000199"],"summary":"Security update for tcmu-runner","upstream":["CVE-2017-1000198","CVE-2017-1000199"]}