Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

SUSE: 2018:0074-1 Critical: Glibc Buffer Overflow And Memory Fixes

suse
Calendar Grey January 12, 2018
Dist Suse Esm H88
Examine the crucial security enhancement for glibc that addresses multiple severe vulnerabilities impacting SUSE environments.
An update that solves 7 vulnerabilities and has three fixes is now available.

Summary

This update for glibc fixes the following issues: - A privilege escalation bug in the realpath() function has been fixed. [CVE-2018-1000001, bsc#1074293] - A memory leak and a buffer overflow in the dynamic ELF loader has been fixed. [CVE-2017-1000408, CVE-2017-1000409, bsc#1071319] - An issue in the code handling RPATHs was fixed that could have been exploited by an attacker to execute code loaded from arbitrary libraries. [CVE-2017-16997, bsc#1073231] - A potential crash caused by a use-after-free bug in pthread_create() has been fixed. [bsc#1053188] - A bug that prevented users to build shared objects which use the optimized libmvec.so API has been fixed. [bsc#1070905] - A memory leak in the glob() function has been fixed. [CVE-2017-15670,

References

#1051042 #1053188 #1063675 #1064569 #1064580

#1064583 #1070905 #1071319 #1073231 #1074293

Cross- CVE-2017-1000408 CVE-2017-1000409 CVE-2017-15670

CVE-2017-15671 CVE-2017-15804 CVE-2017-16997

CVE-2018-1000001

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP3

SUSE Linux Enterprise Software Development Kit 12-SP2

SUSE Linux Enterprise Server for Raspberry Pi 12-SP2

SUSE Linux Enterprise Server 12-SP3

SUSE Linux Enterprise Server 12-SP2

SUSE Linux Enterprise Desktop 12-SP3

SUSE Linux Enterprise Desktop 12-SP2

SUSE CaaS Platform ALL

OpenStack Cloud Magnum Orchestration 7

https://www.suse.com/security/cve/CVE-2017-1000408.html

https://www.suse.com/security/cve/CVE-2017-1000409.html

https://www.suse.com/sec...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:0074-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here