Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2015:0526-1

Опубликовано: 06 мар. 2015
Источник: suse-cvrf

Описание

Security update for glibc

glibc has been updated to fix four security issues.

These security issues were fixed:

  • CVE-2014-7817: The wordexp function in GNU C Library (aka glibc) 2.21 did not enforce the WRDE_NOCMD flag, which allowed context-dependent attackers to execute arbitrary commands, as demonstrated by input containing '$((...))' (bnc#906371).
  • CVE-2015-1472: Heap buffer overflow in glibc swscanf (bnc#916222).
  • CVE-2014-9402: Denial of service in getnetbyname function (bnc#910599).
  • CVE-2013-7423: Getaddrinfo() writes DNS queries to random file descriptors under high load (bnc#915526).

These non-security issues were fixed:

  • Fix infinite loop in check_pf (bsc#909053)
  • Restore warning about execution permission, it is still needed for noexec mounts (bsc#915985).
  • Don't touch user-controlled stdio locks in forked child (bsc#864081)
  • Don't use gcc extensions for non-gcc compilers (bsc#905313)

Список пакетов

SUSE Linux Enterprise Desktop 12
glibc-2.19-20.3
glibc-32bit-2.19-20.3
glibc-devel-2.19-20.3
glibc-devel-32bit-2.19-20.3
glibc-i18ndata-2.19-20.3
glibc-locale-2.19-20.3
glibc-locale-32bit-2.19-20.3
nscd-2.19-20.3
SUSE Linux Enterprise Server 12
glibc-2.19-20.3
glibc-32bit-2.19-20.3
glibc-devel-2.19-20.3
glibc-devel-32bit-2.19-20.3
glibc-html-2.19-20.3
glibc-i18ndata-2.19-20.3
glibc-info-2.19-20.3
glibc-locale-2.19-20.3
glibc-locale-32bit-2.19-20.3
glibc-profile-2.19-20.3
glibc-profile-32bit-2.19-20.3
nscd-2.19-20.3
SUSE Linux Enterprise Server for SAP Applications 12
glibc-2.19-20.3
glibc-32bit-2.19-20.3
glibc-devel-2.19-20.3
glibc-devel-32bit-2.19-20.3
glibc-html-2.19-20.3
glibc-i18ndata-2.19-20.3
glibc-info-2.19-20.3
glibc-locale-2.19-20.3
glibc-locale-32bit-2.19-20.3
glibc-profile-2.19-20.3
glibc-profile-32bit-2.19-20.3
nscd-2.19-20.3
SUSE Linux Enterprise Software Development Kit 12
glibc-devel-static-2.19-20.3

Описание

The send_dg function in resolv/res_send.c in GNU C Library (aka glibc or libc6) before 2.20 does not properly reuse file descriptors, which allows remote attackers to send DNS queries to unintended locations via a large number of requests that trigger a call to the getaddrinfo function.


Затронутые продукты
SUSE Linux Enterprise Desktop 12:glibc-2.19-20.3
SUSE Linux Enterprise Desktop 12:glibc-32bit-2.19-20.3
SUSE Linux Enterprise Desktop 12:glibc-devel-2.19-20.3
SUSE Linux Enterprise Desktop 12:glibc-devel-32bit-2.19-20.3

Ссылки

Описание

The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containing "$((`...`))".


Затронутые продукты
SUSE Linux Enterprise Desktop 12:glibc-2.19-20.3
SUSE Linux Enterprise Desktop 12:glibc-32bit-2.19-20.3
SUSE Linux Enterprise Desktop 12:glibc-devel-2.19-20.3
SUSE Linux Enterprise Desktop 12:glibc-devel-32bit-2.19-20.3

Ссылки

Описание

The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2.21, when the DNS backend in the Name Service Switch configuration is enabled, allows remote attackers to cause a denial of service (infinite loop) by sending a positive answer while a network name is being process.


Затронутые продукты
SUSE Linux Enterprise Desktop 12:glibc-2.19-20.3
SUSE Linux Enterprise Desktop 12:glibc-32bit-2.19-20.3
SUSE Linux Enterprise Desktop 12:glibc-devel-2.19-20.3
SUSE Linux Enterprise Desktop 12:glibc-devel-32bit-2.19-20.3

Ссылки

Описание

The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during memory allocation, which allows context-dependent attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long line containing wide characters that are improperly handled in a wscanf call.


Затронутые продукты
SUSE Linux Enterprise Desktop 12:glibc-2.19-20.3
SUSE Linux Enterprise Desktop 12:glibc-32bit-2.19-20.3
SUSE Linux Enterprise Desktop 12:glibc-devel-2.19-20.3
SUSE Linux Enterprise Desktop 12:glibc-devel-32bit-2.19-20.3

Ссылки
Уязвимость SUSE-SU-2015:0526-1