Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

SUSE: 2018:0451-1 Important: glibc Memory Leak And Overflow Issues

suse
Calendar Grey February 15, 2018
Dist Suse Esm H88
Ubuntu has rolled out a significant patch for OpenSSL, addressing several critical vulnerabilities to strengthen user protection.
An update that fixes 5 vulnerabilities is now available.

Summary

This update for glibc fixes the following issues: Security issues fixed: - CVE-2017-8804: Fix memory leak after deserialization failure in xdr_bytes, xdr_string (bsc#1037930) - CVE-2017-12132: Reduce EDNS payload size to 1200 bytes (bsc#1051791) - CVE-2018-6485,CVE-2018-6551: Fix integer overflows in internal memalign and malloc functions (bsc#1079036) - CVE-2018-1000001: Avoid underflow of malloced area (bsc#1074293) Non security bugs fixed: - Release read lock after resetting timeout (bsc#1073990) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP3: zypper in -t patch SUSE-SLE-SDK-12-SP3-2018-314=1

References

#1037930 #1051791 #1073990 #1074293 #1079036

Cross- CVE-2017-12132 CVE-2017-8804 CVE-2018-1000001

CVE-2018-6485 CVE-2018-6551

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP3

SUSE Linux Enterprise Software Development Kit 12-SP2

SUSE Linux Enterprise Server for Raspberry Pi 12-SP2

SUSE Linux Enterprise Server 12-SP3

SUSE Linux Enterprise Server 12-SP2

SUSE Linux Enterprise Desktop 12-SP3

SUSE Linux Enterprise Desktop 12-SP2

SUSE CaaS Platform ALL

OpenStack Cloud Magnum Orchestration 7

https://www.suse.com/security/cve/CVE-2017-12132.html

https://www.suse.com/security/cve/CVE-2017-8804.html

https://www.suse.com/security/cve/CVE-2018-1000001.html

https://www.suse.com/security/cve/CVE-2018-6485.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:0451-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here