Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2021:1165-1

Опубликовано: 13 апр. 2021
Источник: suse-cvrf

Описание

Security update for glibc

This update for glibc fixes the following issues:

  • CVE-2020-27618: Accept redundant shift sequences in IBM1364 (bsc#1178386)
  • CVE-2020-29562: Fix incorrect UCS4 inner loop bounds (bsc#1179694)
  • CVE-2020-29573: Harden printf against non-normal long double values (bsc#1179721)
  • Check vector support in memmove ifunc-selector (bsc#1184034)

Список пакетов

Container suse/ltss/sle12.5/sles12sp5:latest
glibc-2.22-114.8.3
Container suse/sles12sp4:latest
glibc-2.22-114.8.3
Container suse/sles12sp5:latest
glibc-2.22-114.8.3
Image SLES12-SP4-Azure-BYOS
glibc-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-locale-2.22-114.8.3
nscd-2.22-114.8.3
Image SLES12-SP4-EC2-HVM-BYOS
glibc-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-locale-2.22-114.8.3
nscd-2.22-114.8.3
Image SLES12-SP4-GCE-BYOS
glibc-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-locale-2.22-114.8.3
nscd-2.22-114.8.3
Image SLES12-SP4-SAP-Azure
glibc-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-locale-2.22-114.8.3
nscd-2.22-114.8.3
Image SLES12-SP4-SAP-Azure-BYOS
glibc-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-locale-2.22-114.8.3
nscd-2.22-114.8.3
Image SLES12-SP4-SAP-Azure-LI-BYOS-Production
glibc-2.22-114.8.3
glibc-32bit-2.22-114.8.3
glibc-devel-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-locale-2.22-114.8.3
nscd-2.22-114.8.3
Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production
glibc-2.22-114.8.3
glibc-32bit-2.22-114.8.3
glibc-devel-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-locale-2.22-114.8.3
nscd-2.22-114.8.3
Image SLES12-SP4-SAP-EC2-HVM
glibc-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-locale-2.22-114.8.3
nscd-2.22-114.8.3
Image SLES12-SP4-SAP-EC2-HVM-BYOS
glibc-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-locale-2.22-114.8.3
nscd-2.22-114.8.3
Image SLES12-SP4-SAP-GCE
glibc-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-locale-2.22-114.8.3
nscd-2.22-114.8.3
Image SLES12-SP4-SAP-GCE-BYOS
glibc-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-locale-2.22-114.8.3
nscd-2.22-114.8.3
Image SLES12-SP5-Azure-BYOS
glibc-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-locale-2.22-114.8.3
nscd-2.22-114.8.3
Image SLES12-SP5-Azure-Basic-On-Demand
glibc-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-locale-2.22-114.8.3
nscd-2.22-114.8.3
Image SLES12-SP5-Azure-HPC-BYOS
glibc-2.22-114.8.3
glibc-32bit-2.22-114.8.3
glibc-devel-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-locale-2.22-114.8.3
nscd-2.22-114.8.3
Image SLES12-SP5-Azure-HPC-On-Demand
glibc-2.22-114.8.3
glibc-32bit-2.22-114.8.3
glibc-devel-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-locale-2.22-114.8.3
nscd-2.22-114.8.3
Image SLES12-SP5-Azure-SAP-BYOS
glibc-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-locale-2.22-114.8.3
nscd-2.22-114.8.3
Image SLES12-SP5-Azure-SAP-On-Demand
glibc-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-locale-2.22-114.8.3
nscd-2.22-114.8.3
Image SLES12-SP5-Azure-Standard-On-Demand
glibc-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-locale-2.22-114.8.3
nscd-2.22-114.8.3
Image SLES12-SP5-EC2-BYOS
glibc-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-locale-2.22-114.8.3
nscd-2.22-114.8.3
Image SLES12-SP5-EC2-ECS-On-Demand
glibc-2.22-114.8.3
glibc-locale-2.22-114.8.3
nscd-2.22-114.8.3
Image SLES12-SP5-EC2-On-Demand
glibc-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-locale-2.22-114.8.3
nscd-2.22-114.8.3
Image SLES12-SP5-EC2-SAP-BYOS
glibc-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-locale-2.22-114.8.3
nscd-2.22-114.8.3
Image SLES12-SP5-EC2-SAP-On-Demand
glibc-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-locale-2.22-114.8.3
nscd-2.22-114.8.3
Image SLES12-SP5-GCE-BYOS
glibc-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-locale-2.22-114.8.3
nscd-2.22-114.8.3
Image SLES12-SP5-GCE-On-Demand
glibc-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-locale-2.22-114.8.3
nscd-2.22-114.8.3
Image SLES12-SP5-GCE-SAP-BYOS
glibc-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-locale-2.22-114.8.3
nscd-2.22-114.8.3
Image SLES12-SP5-GCE-SAP-On-Demand
glibc-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-locale-2.22-114.8.3
nscd-2.22-114.8.3
Image SLES12-SP5-OCI-BYOS-BYOS
glibc-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-locale-2.22-114.8.3
nscd-2.22-114.8.3
Image SLES12-SP5-OCI-BYOS-SAP-BYOS
glibc-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-locale-2.22-114.8.3
nscd-2.22-114.8.3
Image SLES12-SP5-SAP-Azure-LI-BYOS-Production
glibc-2.22-114.8.3
glibc-32bit-2.22-114.8.3
glibc-devel-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-locale-2.22-114.8.3
nscd-2.22-114.8.3
Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production
glibc-2.22-114.8.3
glibc-32bit-2.22-114.8.3
glibc-devel-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-locale-2.22-114.8.3
nscd-2.22-114.8.3
SUSE Linux Enterprise Server 12 SP4-LTSS
glibc-2.22-114.8.3
glibc-32bit-2.22-114.8.3
glibc-devel-2.22-114.8.3
glibc-devel-32bit-2.22-114.8.3
glibc-html-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-info-2.22-114.8.3
glibc-locale-2.22-114.8.3
glibc-locale-32bit-2.22-114.8.3
glibc-profile-2.22-114.8.3
glibc-profile-32bit-2.22-114.8.3
nscd-2.22-114.8.3
SUSE Linux Enterprise Server 12 SP5
glibc-2.22-114.8.3
glibc-32bit-2.22-114.8.3
glibc-devel-2.22-114.8.3
glibc-devel-32bit-2.22-114.8.3
glibc-html-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-info-2.22-114.8.3
glibc-locale-2.22-114.8.3
glibc-locale-32bit-2.22-114.8.3
glibc-profile-2.22-114.8.3
glibc-profile-32bit-2.22-114.8.3
nscd-2.22-114.8.3
SUSE Linux Enterprise Server for SAP Applications 12 SP4
glibc-2.22-114.8.3
glibc-32bit-2.22-114.8.3
glibc-devel-2.22-114.8.3
glibc-devel-32bit-2.22-114.8.3
glibc-html-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-info-2.22-114.8.3
glibc-locale-2.22-114.8.3
glibc-locale-32bit-2.22-114.8.3
glibc-profile-2.22-114.8.3
glibc-profile-32bit-2.22-114.8.3
nscd-2.22-114.8.3
SUSE Linux Enterprise Server for SAP Applications 12 SP5
glibc-2.22-114.8.3
glibc-32bit-2.22-114.8.3
glibc-devel-2.22-114.8.3
glibc-devel-32bit-2.22-114.8.3
glibc-html-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-info-2.22-114.8.3
glibc-locale-2.22-114.8.3
glibc-locale-32bit-2.22-114.8.3
glibc-profile-2.22-114.8.3
glibc-profile-32bit-2.22-114.8.3
nscd-2.22-114.8.3
SUSE Linux Enterprise Software Development Kit 12 SP5
glibc-devel-static-2.22-114.8.3
glibc-info-2.22-114.8.3
SUSE OpenStack Cloud 9
glibc-2.22-114.8.3
glibc-32bit-2.22-114.8.3
glibc-devel-2.22-114.8.3
glibc-devel-32bit-2.22-114.8.3
glibc-html-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-info-2.22-114.8.3
glibc-locale-2.22-114.8.3
glibc-locale-32bit-2.22-114.8.3
glibc-profile-2.22-114.8.3
glibc-profile-32bit-2.22-114.8.3
nscd-2.22-114.8.3
SUSE OpenStack Cloud Crowbar 9
glibc-2.22-114.8.3
glibc-32bit-2.22-114.8.3
glibc-devel-2.22-114.8.3
glibc-devel-32bit-2.22-114.8.3
glibc-html-2.22-114.8.3
glibc-i18ndata-2.22-114.8.3
glibc-info-2.22-114.8.3
glibc-locale-2.22-114.8.3
glibc-locale-32bit-2.22-114.8.3
glibc-profile-2.22-114.8.3
glibc-profile-32bit-2.22-114.8.3
nscd-2.22-114.8.3

Описание

The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399 encodings, fails to advance the input state, which could lead to an infinite loop in applications, resulting in a denial of service, a different vulnerability from CVE-2016-10228.


Затронутые продукты
Container suse/ltss/sle12.5/sles12sp5:latest:glibc-2.22-114.8.3
Container suse/sles12sp4:latest:glibc-2.22-114.8.3
Container suse/sles12sp5:latest:glibc-2.22-114.8.3
Image SLES12-SP4-Azure-BYOS:glibc-2.22-114.8.3

Ссылки

Описание

The iconv function in the GNU C Library (aka glibc or libc6) 2.30 to 2.32, when converting UCS4 text containing an irreversible character, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service.


Затронутые продукты
Container suse/ltss/sle12.5/sles12sp5:latest:glibc-2.22-114.8.3
Container suse/sles12sp4:latest:glibc-2.22-114.8.3
Container suse/sles12sp5:latest:glibc-2.22-114.8.3
Image SLES12-SP4-Azure-BYOS:glibc-2.22-114.8.3

Ссылки

Описание

sysdeps/i386/ldbl2mpn.c in the GNU C Library (aka glibc or libc6) before 2.23 on x86 targets has a stack-based buffer overflow if the input to any of the printf family of functions is an 80-bit long double with a non-canonical bit pattern, as seen when passing a \x00\x04\x00\x00\x00\x00\x00\x00\x00\x04 value to sprintf. NOTE: the issue does not affect glibc by default in 2016 or later (i.e., 2.23 or later) because of commits made in 2015 for inlining of C99 math functions through use of GCC built-ins. In other words, the reference to 2.23 is intentional despite the mention of "Fixed for glibc 2.33" in the 26649 reference.


Затронутые продукты
Container suse/ltss/sle12.5/sles12sp5:latest:glibc-2.22-114.8.3
Container suse/sles12sp4:latest:glibc-2.22-114.8.3
Container suse/sles12sp5:latest:glibc-2.22-114.8.3
Image SLES12-SP4-Azure-BYOS:glibc-2.22-114.8.3

Ссылки
Уязвимость SUSE-SU-2021:1165-1