{"id":"openSUSE-SU-2021:3804-1","summary":"Security update for netcdf","details":"This update for netcdf fixes the following issues:\n\n- Fixed multiple vulnerabilities in ezXML:\n    CVE-2019-20007, CVE-2019-20006, CVE-2019-20201, CVE-2019-20202,\n    CVE-2019-20199, CVE-2019-20200, CVE-2019-20198, CVE-2021-26221,\n    CVE-2021-26222, CVE-2021-30485, CVE-2021-31229, CVE-2021-31347,\n    CVE-2021-31348, CVE-2021-31598 (bsc#1191856)\n   Note:\n   * CVE-2021-26220 https://sourceforge.net/p/ezxml/bugs/23\n     not relevant for netcdf: code isn't used.\n   * CVE-2019-20005 https://sourceforge.net/p/ezxml/bugs/14\n     Issue cannot be reproduced and no patch is available upstream.\n","modified":"2026-03-11T07:33:20.334879Z","published":"2021-11-25T12:47:43Z","related":["CVE-2019-20005","CVE-2019-20006","CVE-2019-20007","CVE-2019-20198","CVE-2019-20199","CVE-2019-20200","CVE-2019-20201","CVE-2019-20202","CVE-2021-26220","CVE-2021-26221","CVE-2021-26222","CVE-2021-30485","CVE-2021-31229","CVE-2021-31347","CVE-2021-31348","CVE-2021-31598"],"upstream":["CVE-2019-20005","CVE-2019-20006","CVE-2019-20007","CVE-2019-20198","CVE-2019-20199","CVE-2019-20200","CVE-2019-20201","CVE-2019-20202","CVE-2021-26220","CVE-2021-26221","CVE-2021-26222","CVE-2021-30485","CVE-2021-31229","CVE-2021-31347","CVE-2021-31348","CVE-2021-31598"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/DM4S3HXSBD3QQY6J6J2S4KVWTO63OS7U/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1191856"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-20005"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-20006"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-20007"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-20198"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-20199"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-20200"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-20201"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-20202"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-26220"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-26221"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-26222"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-30485"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-31229"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-31347"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-31348"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-31598"}],"affected":[{"package":{"name":"netcdf","ecosystem":"openSUSE:Leap 15.3","purl":"pkg:rpm/opensuse/netcdf&distro=openSUSE%20Leap%2015.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.6.1-5.7.1"}]}],"ecosystem_specific":{"binaries":[{"libnetcdf13":"4.6.1-5.7.1","netcdf-openmpi-devel-data":"4.6.1-5.7.1","netcdf-openmpi-devel-static":"4.6.1-5.7.1","netcdf-openmpi-devel":"4.6.1-5.7.1","netcdf-openmpi":"4.6.1-5.7.1","libnetcdf13-32bit":"4.6.1-5.7.1","libnetcdf13-openmpi-32bit":"4.6.1-5.7.1","libnetcdf13-openmpi":"4.6.1-5.7.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2021:3804-1.json"}},{"package":{"name":"netcdf-openmpi","ecosystem":"openSUSE:Leap 15.3","purl":"pkg:rpm/opensuse/netcdf-openmpi&distro=openSUSE%20Leap%2015.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.6.1-5.7.1"}]}],"ecosystem_specific":{"binaries":[{"netcdf-openmpi-devel-static":"4.6.1-5.7.1","netcdf-openmpi-devel":"4.6.1-5.7.1","netcdf-openmpi":"4.6.1-5.7.1","libnetcdf13-32bit":"4.6.1-5.7.1","libnetcdf13-openmpi-32bit":"4.6.1-5.7.1","libnetcdf13-openmpi":"4.6.1-5.7.1","libnetcdf13":"4.6.1-5.7.1","netcdf-openmpi-devel-data":"4.6.1-5.7.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2021:3804-1.json"}}],"schema_version":"1.7.5"}