Security update for glibc
This update for glibc fixes the following issues: Security issues: - CVE-2017-8804: Fix memory leak after deserialization failure in xdr_bytes, xdr_string (bsc#1037930) - CVE-2017-12132: Reduce EDNS payload size to 1200 bytes (bsc#1051791) - CVE-2018-6485,CVE-2018-6551: Fix integer overflows in internal memalign and malloc functions (bsc#1079036) - CVE-2018-1000001: Avoid underflow of malloced area in realpath (bsc#1074293) Also a non security issue was fixed: - Do not fail if one of the two responses to AF_UNSPEC fails (bsc#978209)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for glibc fixes the following issues: Security issues: - CVE-2017-8804: Fix memory leak after deserialization failure in xdr_bytes, xdr_string (bsc#1037930) - CVE-2017-12132: Reduce EDNS payload size to 1200 bytes (bsc#1051791) - CVE-2018-6485,CVE-2018-6551: Fix integer overflows in internal memalign and malloc functions (bsc#1079036) - CVE-2018-1000001: Avoid underflow of malloced area in realpath (bsc#1074293) Also a non security issue was fixed: - Do not fail if one of the two responses to AF_UNSPEC fails (bsc#978209)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1037930
- https://bugzilla.suse.com/1051791
- https://bugzilla.suse.com/1074293
- https://bugzilla.suse.com/1079036
- https://bugzilla.suse.com/978209
- https://www.suse.com/security/cve/CVE-2017-12132
- https://www.suse.com/security/cve/CVE-2017-8804
- https://www.suse.com/security/cve/CVE-2018-1000001
- https://www.suse.com/security/cve/CVE-2018-6485
- https://www.suse.com/security/cve/CVE-2018-6551
- https://www.suse.com/support/update/announcement/2018/suse-su-20180565-1/