Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

SUSE 10 SP4 LTSS SUSE-SU-2014:1119-1 Critical: glibc Buffer Overflow

suse
Calendar Grey September 12, 2014
Scroller Suse
The Debian Security Notice tackles severe vulnerabilities in OpenSSL, mitigating various attacks to enhance the security of server environments.
An update that solves three vulnerabilities and has four An update that solves three vulnerabilities and has four An update that solves three vulnerabilities and has four fixes is ...

Summary

This glibc update fixes a critical privilege escalation problem and the following security and non security issues: * bnc#892073: An off-by-one error leading to a heap-based buffer overflow was found in __gconv_translit_find(). An exploit that targets the problem is publicly available. (CVE-2014-5119) * bnc#772242: Replace scope handing with master state * bnc#779320: Fix buffer overflow in strcoll (CVE-2012-4412) * bnc#818630: Fall back to localhost if no nameserver defined * bnc#828235: Fix missing character in IBM-943 charset * bnc#828637: Fix use of alloca in gaih_inet * bnc#834594: Fix readdir_r with long file names (CVE-2013-4237) Security Issues: * CVE-2014-5119 * CVE-2013-4237

References

#772242 #779320 #818630 #828235 #828637 #834594

#892073

Cross- CVE-2012-4412 CVE-2013-4237 CVE-2014-5119

Affected Products:

SUSE Linux Enterprise Server 10 SP4 LTSS

https://www.suse.com/security/cve/CVE-2012-4412.html

https://www.suse.com/security/cve/CVE-2013-4237.html

https://www.suse.com/security/cve/CVE-2014-5119.html

https://scc.suse.com:443/patches/

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:1119-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.