Описание
Security update for gc
This update for gc fixes the following issues:
- integer overflow in GC_MALLOC_ATOMIC() (CVE-2016-9427, bsc#1011276)
Список пакетов
SUSE Linux Enterprise Desktop 12 SP1
libgc1-7.2d-5.1
SUSE Linux Enterprise Desktop 12 SP2
libgc1-7.2d-5.1
SUSE Linux Enterprise Server 12 SP1
libgc1-7.2d-5.1
SUSE Linux Enterprise Server 12 SP2
libgc1-7.2d-5.1
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2
libgc1-7.2d-5.1
SUSE Linux Enterprise Server for SAP Applications 12 SP1
libgc1-7.2d-5.1
SUSE Linux Enterprise Server for SAP Applications 12 SP2
libgc1-7.2d-5.1
SUSE Linux Enterprise Software Development Kit 12 SP1
gc-devel-7.2d-5.1
SUSE Linux Enterprise Software Development Kit 12 SP2
gc-devel-7.2d-5.1
Ссылки
- Link for SUSE-SU-2016:3057-1
- E-Mail link for SUSE-SU-2016:3057-1
- SUSE Security Ratings
- SUSE Bug 1011276
- SUSE CVE CVE-2016-9427 page
Описание
Integer overflow vulnerability in bdwgc before 2016-09-27 allows attackers to cause client of bdwgc denial of service (heap buffer overflow crash) and possibly execute arbitrary code via huge allocation.
Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP1:libgc1-7.2d-5.1
SUSE Linux Enterprise Desktop 12 SP2:libgc1-7.2d-5.1
SUSE Linux Enterprise Server 12 SP1:libgc1-7.2d-5.1
SUSE Linux Enterprise Server 12 SP2:libgc1-7.2d-5.1
Ссылки
- CVE-2016-9427
- SUSE Bug 1011276
- SUSE Bug 1011293