Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

openSUSE Leap 15.0: 2018:2159-1 Moderate: glibc Memory Issues from DoS

opensuse
Calendar Grey August 1, 2018
Dist Opensuse Esm H88
OpenSUSE faces security issues with glibc that demand urgent fixes. Key vulnerabilities and their solutions include buffer overflow, memory corruption, and stack overflow
An update that solves three vulnerabilities and has two fixes is now available.

Description

This update for glibc fixes the following security issues:

- CVE-2017-18269: An SSE2-optimized memmove implementation for i386 did

not correctly perform the overlapping memory check if the source memory

range spaned the middle of the address space, resulting in corrupt data

being produced by the copy operation. This may have disclosed

information to context-dependent attackers, resulted in a denial of

service or code execution (bsc#1094150).

- CVE-2018-11236: Prevent integer overflow on 32-bit architectures when

processing very long pathname arguments to the realpath function,

leading to a stack-based buffer overflow (bsc#1094161).

- CVE-2018-11237: An AVX-512-optimized implementation of the mempcpy

function may have writen data beyond the target buffer, leading to a

buffer overflow in __mempcpy_avx512_no_vzeroupper (bsc#1092877,

bsc#1094154).

This update was imported from the SUSE:SLE-15:Update update project.

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.0:

zypper in -t patch openSUSE-2018-788=1

Package List

- openSUSE Leap 15.0 (i586 i686 x86_64):

glibc-2.26-lp150.11.6.120

glibc-debuginfo-2.26-lp150.11.6.120

glibc-debugsource-2.26-lp150.11.6.120

glibc-devel-2.26-lp150.11.6.120

glibc-devel-debuginfo-2.26-lp150.11.6.120

glibc-devel-static-2.26-lp150.11.6.120

glibc-locale-2.26-lp150.11.6.120

glibc-locale-debuginfo-2.26-lp150.11.6.120

glibc-profile-2.26-lp150.11.6.120

- openSUSE Leap 15.0 (i586 x86_64):

glibc-extra-2.26-lp150.11.6.120

glibc-extra-debuginfo-2.26-lp150.11.6.120

glibc-utils-2.26-lp150.11.6.120

glibc-utils-debuginfo-2.26-lp150.11.6.120

glibc-utils-src-debugsource-2.26-lp150.11.6.120

nscd-2.26-lp150.11.6.120

nscd-debuginfo-2.26-lp150.11.6.120

- openSUSE Leap 15.0 (x86_64):

glibc-32bit-2.26-lp150.11.6.120

glibc-32bit-debuginfo-2.26-lp150.11.6.120

glibc-devel-32bit-2.26-lp150.11.6.120

glibc-devel-32bit-debuginfo-2.26-lp150.11.6.120

glibc-devel-static-32bit-2.26-lp150.11.6.120

glibc-locale-32bit-2.26-lp150.11.6.120

glibc-locale-32bit-debuginfo-2.26-lp150.11.6.120

glibc-profile-32bit-2.26-lp150.11.6.120

glibc-u...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2017-18269.html

https://www.suse.com/security/cve/CVE-2018-11236.html

https://www.suse.com/security/cve/CVE-2018-11237.html

https://bugzilla.suse.com/1082318

https://bugzilla.suse.com/1092877

https://bugzilla.suse.com/1094150

https://bugzilla.suse.com/1094154

https://bugzilla.suse.com/1094161

--

Announcement ID: openSUSE-SU-2018:2159-1
Rating: moderate
Affected Products: openSUSE Leap 15.0 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here