Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2021:1374-1

Опубликовано: 18 окт. 2021
Источник: suse-cvrf

Описание

Security update for glibc

This update for glibc fixes the following issues:

  • CVE-2021-35942: wordexp: handle overflow in positional parameter number (bsc#1187911)
  • CVE-2021-33574: Use __pthread_attr_copy in mq_notify (bsc#1186489)

This update was imported from the SUSE:SLE-15:Update update project.

Список пакетов

openSUSE Leap 15.2
glibc-2.26-lp152.26.9.1
glibc-32bit-2.26-lp152.26.9.1
glibc-devel-2.26-lp152.26.9.1
glibc-devel-32bit-2.26-lp152.26.9.1
glibc-devel-static-2.26-lp152.26.9.1
glibc-devel-static-32bit-2.26-lp152.26.9.1
glibc-extra-2.26-lp152.26.9.1
glibc-html-2.26-lp152.26.9.1
glibc-i18ndata-2.26-lp152.26.9.1
glibc-info-2.26-lp152.26.9.1
glibc-locale-2.26-lp152.26.9.1
glibc-locale-base-2.26-lp152.26.9.1
glibc-locale-base-32bit-2.26-lp152.26.9.1
glibc-profile-2.26-lp152.26.9.1
glibc-profile-32bit-2.26-lp152.26.9.1
glibc-utils-2.26-lp152.26.9.1
glibc-utils-32bit-2.26-lp152.26.9.1
nscd-2.26-lp152.26.9.1

Описание

The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified other impact.


Затронутые продукты
openSUSE Leap 15.2:glibc-2.26-lp152.26.9.1
openSUSE Leap 15.2:glibc-32bit-2.26-lp152.26.9.1
openSUSE Leap 15.2:glibc-devel-2.26-lp152.26.9.1
openSUSE Leap 15.2:glibc-devel-32bit-2.26-lp152.26.9.1

Ссылки

Описание

The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have been used to ensure correct calculations.


Затронутые продукты
openSUSE Leap 15.2:glibc-2.26-lp152.26.9.1
openSUSE Leap 15.2:glibc-32bit-2.26-lp152.26.9.1
openSUSE Leap 15.2:glibc-devel-2.26-lp152.26.9.1
openSUSE Leap 15.2:glibc-devel-32bit-2.26-lp152.26.9.1

Ссылки
Уязвимость openSUSE-SU-2021:1374-1