shield
Security update for glibc
SUSE-SLE-SDK-12-2015-129
glibc has been updated to fix four security issues. These security issues were fixed: - CVE-2014-7817: The wordexp function in GNU C Library (aka glibc) 2.21 did not enforce the WRDE_NOCMD flag, which allowed context-dependent attackers to execute arbitrary commands, as demonstrated by input containing "$((`...`))" (bnc#906371). - CVE-2015-1472: Heap buffer overflow in glibc swscanf (bnc#916222). - CVE-2014-9402: Denial of service in getnetbyname function (bnc#910599). - CVE-2013-7423: Getaddrinfo() writes DNS queries to random file descriptors under high load (bnc#915526). These non-security issues were fixed: - Fix infinite loop in check_pf (bsc#909053) - Restore warning about execution permission, it is still needed for noexec mounts (bsc#915985). - Don't touch user-controlled stdio locks in forked child (bsc#864081) - Don't use gcc extensions for non-gcc compilers (bsc#905313)
-
Release DateMar 6 2015
-
ReferencesBugzilla: 916222, 910599, 915526, 909053, 915985, 864081, 906371, 905313
CVEs: CVE-2014-9402, CVE-2015-1472, CVE-2013-7423, CVE-2014-7817 -
Typesecurity
-
Severitymoderate
cloud_download Downloads
SUSE Linux Enterprise Software Development Kit 12 ppc64le
-
Packagesglibc
Standard Shared Libraries (from the GNU C Library)glibc-devel-static2.19-20.3 lock src
C library static libraries for -static linking2.19-20.3 lock rpm
SUSE Linux Enterprise Software Development Kit 12 s390x
-
Packagesglibc
Standard Shared Libraries (from the GNU C Library)glibc-devel-static2.19-20.3 lock src
C library static libraries for -static linking2.19-20.3 lock rpm
SUSE Linux Enterprise Software Development Kit 12 x86_64
-
Packagesglibc
Standard Shared Libraries (from the GNU C Library)glibc-devel-static2.19-20.3 lock src
C library static libraries for -static linking2.19-20.3 lock rpm