Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

SUSE 11-SP2: 2016:0470-1 Important: glibc Stack Overflow Threats

suse
Calendar Grey February 16, 2016
Dist Suse Esm H88
SUSE has released a Security Update tackling 12 vulnerabilities in libxml2, bolstering overall system integrity and mitigating severe threats.
An update that solves 10 vulnerabilities and has four fixes An update that solves 10 vulnerabilities and has four fixes An update that solves 10 vulnerabilities and has four fixes ...

Summary

This update for glibc fixes the following issues: - CVE-2015-7547: A stack-based buffer overflow in getaddrinfo allowed remote attackers to cause a crash or execute arbitrary code via crafted and timed DNS responses (bsc#961721) - CVE-2015-8777: Insufficient checking of LD_POINTER_GUARD environment variable allowed local attackers to bypass the pointer guarding protection of the dynamic loader on set-user-ID and set-group-ID programs (bsc#950944) - CVE-2015-8776: Out-of-range time values passed to the strftime function may cause it to crash, leading to a denial of service, or potentially disclosure information (bsc#962736) - CVE-2015-8778: Integer overflow in hcreate and hcreate_r could have caused an out-of-bound memory access. leading to application crashes or,

References

#830257 #847227 #863499 #892065 #918187 #920338

#927080 #945779 #950944 #961721 #962736 #962737

#962738 #962739

Cross- CVE-2013-2207 CVE-2013-4458 CVE-2014-8121

CVE-2014-9761 CVE-2015-1781 CVE-2015-7547

CVE-2015-8776 CVE-2015-8777 CVE-2015-8778

CVE-2015-8779

Affected Products:

SUSE Linux Enterprise Server 11-SP2-LTSS

SUSE Linux Enterprise Debuginfo 11-SP2

https://www.suse.com/security/cve/CVE-2013-2207.html

https://www.suse.com/security/cve/CVE-2013-4458.html

https://www.suse.com/security/cve/CVE-2014-8121.html

https://www.suse.com/security/cve/CVE-2014-9761.html

https://www.suse.com/security/cve/CVE-2015-1781.html

https://www.suse.com/security/cve/CVE-2015-7547.html

https://www.suse.com/security/cve/CVE-2015-8776.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:0470-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here