Security update for glibc
This update for glibc contains the following fixes: * Fix integer overflows in malloc (CVE-2013-4332, bnc#839870) * Fix buffer overflow in glob (bnc#691365) * Fix buffer overflow in strcoll (CVE-2012-4412, bnc#779320) * Update mount flags in <sys/mount.h> (bnc#791928) * Fix buffer overrun in regexp matcher (CVE-2013-0242, bnc#801246) * Fix memory leaks in dlopen (bnc#811979) * Fix stack overflow in getaddrinfo with many results (CVE-2013-1914, bnc#813121) * Fix check for XEN build in glibc_post_upgrade that causes missing init re-exec (bnc#818628) * Don't raise UNDERFLOW in tan/tanf for small but normal argument (bnc#819347) * Properly cross page boundary in SSE4.2 implementation of strcmp (bnc#822210) * Fix robust mutex handling after fork (bnc#827811) * Fix missing character in IBM-943 charset (bnc#828235) * Fix use of alloca in gaih_inet (bnc#828637) * Initialize pointer guard also in static executables (CVE-2013-4788, bnc#830268) * Fix readdir_r with long file names (CVE-2013-4237, bnc#834594). Security Issues: * CVE-2012-4412 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4412> * CVE-2013-0242 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0242> * CVE-2013-1914 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1914> * CVE-2013-4237 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4237> * CVE-2013-4332 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4332> * CVE-2013-4788 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4788>
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for glibc contains the following fixes: * Fix integer overflows in malloc (CVE-2013-4332, bnc#839870) * Fix buffer overflow in glob (bnc#691365) * Fix buffer overflow in strcoll (CVE-2012-4412, bnc#779320) * Update mount flags in <sys/mount.h> (bnc#791928) * Fix buffer overrun in regexp matcher (CVE-2013-0242, bnc#801246) * Fix memory leaks in dlopen (bnc#811979) * Fix stack overflow in getaddrinfo with many results (CVE-2013-1914, bnc#813121) * Fix check for XEN build in glibc_post_upgrade that causes missing init re-exec (bnc#818628) * Don't raise UNDERFLOW in tan/tanf for small but normal argument (bnc#819347) * Properly cross page boundary in SSE4.2 implementation of strcmp (bnc#822210) * Fix robust mutex handling after fork (bnc#827811) * Fix missing character in IBM-943 charset (bnc#828235) * Fix use of alloca in gaih_inet (bnc#828637) * Initialize pointer guard also in static executables (CVE-2013-4788, bnc#830268) * Fix readdir_r with long file names (CVE-2013-4237, bnc#834594). Security Issues: * CVE-2012-4412 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4412> * CVE-2013-0242 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0242> * CVE-2013-1914 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1914> * CVE-2013-4237 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4237> * CVE-2013-4332 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4332> * CVE-2013-4788 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4788>
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/684534
- https://bugzilla.suse.com/691365
- https://bugzilla.suse.com/741345
- https://bugzilla.suse.com/743689
- https://bugzilla.suse.com/744996
- https://bugzilla.suse.com/745658
- https://bugzilla.suse.com/746824
- https://bugzilla.suse.com/747768
- https://bugzilla.suse.com/750741
- https://bugzilla.suse.com/760795
- https://bugzilla.suse.com/763512
- https://bugzilla.suse.com/767266
- https://bugzilla.suse.com/770891
- https://bugzilla.suse.com/775690
- https://bugzilla.suse.com/777233
- https://bugzilla.suse.com/779320
- https://bugzilla.suse.com/783060
- https://bugzilla.suse.com/785041
- https://bugzilla.suse.com/791928
- https://bugzilla.suse.com/793146
- https://bugzilla.suse.com/795129
- https://bugzilla.suse.com/801246
- https://bugzilla.suse.com/811979
- https://bugzilla.suse.com/813121
- https://bugzilla.suse.com/818628
- https://bugzilla.suse.com/819347
- https://bugzilla.suse.com/822210
- https://bugzilla.suse.com/827811
- https://bugzilla.suse.com/828235
- https://bugzilla.suse.com/828637
- https://bugzilla.suse.com/830268
- https://bugzilla.suse.com/834594
- https://bugzilla.suse.com/836746
- https://bugzilla.suse.com/839870
- https://bugzilla.suse.com/844309
- https://bugzilla.suse.com/864081
- https://bugzilla.suse.com/882600
- https://bugzilla.suse.com/887022
- https://bugzilla.suse.com/892073
- https://bugzilla.suse.com/894553
- https://bugzilla.suse.com/894556
- https://bugzilla.suse.com/906371
- https://bugzilla.suse.com/909053
- https://bugzilla.suse.com/910599
- https://bugzilla.suse.com/913646
- https://bugzilla.suse.com/915526
- https://bugzilla.suse.com/916222
- https://bugzilla.suse.com/918233
- https://www.suse.com/security/cve/CVE-2012-0864
- https://www.suse.com/security/cve/CVE-2012-3404
- https://www.suse.com/security/cve/CVE-2012-3405
- https://www.suse.com/security/cve/CVE-2012-3406
- https://www.suse.com/security/cve/CVE-2012-3480
- https://www.suse.com/security/cve/CVE-2012-4412
- https://www.suse.com/security/cve/CVE-2012-6656
- https://www.suse.com/security/cve/CVE-2013-0242
- https://www.suse.com/security/cve/CVE-2013-1914
- https://www.suse.com/security/cve/CVE-2013-4237
- https://www.suse.com/security/cve/CVE-2013-4332
- https://www.suse.com/security/cve/CVE-2013-4357
- https://www.suse.com/security/cve/CVE-2013-4788
- https://www.suse.com/security/cve/CVE-2013-7423
- https://www.suse.com/security/cve/CVE-2014-5119
- https://www.suse.com/security/cve/CVE-2014-6040
- https://www.suse.com/security/cve/CVE-2014-7817
- https://www.suse.com/security/cve/CVE-2014-9402
- https://www.suse.com/security/cve/CVE-2015-0235
- https://www.suse.com/security/cve/CVE-2015-1472
- https://www.suse.com/support/update/announcement/2015/suse-su-20150551-1/