Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 501
Alerts This Week
Warning Icon 1 501

SUSE: 2022:5678-3 Urgent: OpenSSL Vulnerability Fix Released

suse
Calendar Grey September 15, 2014
Scroller Suse
Canonical Security Patch addresses severe flaws in systemd, bolstering operational security and mitigating risks.
An update that solves four vulnerabilities and has one An update that solves four vulnerabilities and has one An update that solves four vulnerabilities and has one errata is now a...

Summary

This glibc update fixes a critical privilege escalation problem and two additional issues: * bnc#892073: An off-by-one error leading to a heap-based buffer overflow was found in __gconv_translit_find(). An exploit that targets the problem is publicly available. (CVE-2014-5119) * bnc#836746: Avoid race between {, __de}allocate_stack and __reclaim_stacks during fork. * bnc#844309: Fixed various overflows, reading large /etc/hosts or long names. (CVE-2013-4357) * bnc#894553, bnc#894556: Fixed various crashes on invalid input in IBM gconv modules. (CVE-2014-6040, CVE-2012-6656) Security Issues: * CVE-2012-6656 * CVE-2013-4357 * CVE-2014-5119

References

#836746 #844309 #892073 #894553 #894556

Cross- CVE-2012-6656 CVE-2013-4357 CVE-2014-5119

CVE-2014-6040

Affected Products:

SUSE Linux Enterprise Server 11 SP2 LTSS

https://www.suse.com/security/cve/CVE-2012-6656.html

https://www.suse.com/security/cve/CVE-2013-4357.html

https://www.suse.com/security/cve/CVE-2014-5119.html

https://www.suse.com/security/cve/CVE-2014-6040.html

https://scc.suse.com:443/patches/

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:1129-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.