Oval Definition:oval:org.opensuse.security:def:58943
Revision Date:2020-12-01Version:1
Title:Security update for glibc (Important)
Description:

This update for glibc fixes the following issues:

- A privilege escalation bug in the realpath() function has been fixed. [CVE-2018-1000001, bsc#1074293]

- A memory leak and a buffer overflow in the dynamic ELF loader has been fixed. [CVE-2017-1000408, CVE-2017-1000409, bsc#1071319]

- An issue in the code handling RPATHs was fixed that could have been exploited by an attacker to execute code loaded from arbitrary libraries. [CVE-2017-16997, bsc#1073231]

- A potential crash caused by a use-after-free bug in pthread_create() has been fixed. [bsc#1053188]

- A bug that prevented users to build shared objects which use the optimized libmvec.so API has been fixed. [bsc#1070905]

- A memory leak in the glob() function has been fixed. [CVE-2017-15670, CVE-2017-15671, CVE-2017-15804, bsc#1064569, bsc#1064580, bsc#1064583]

- A bug that would lose the syscall error code value in case of crashes has been fixed. [bsc#1063675]
Family:unixClass:patch
Status:Reference(s):1000396
1001299
1051042
1053043
1053188
1063675
1064569
1064580
1064583
1066223
1070905
1071319
1073230
1073231
1074293
1076017
1083488
1085114
1085447
1086247
1088004
1088009
1092100
1094555
1108382
1109137
1111188
1111331
1118987
1119086
1120902
1121263
1121753
1122706
1125580
1126961
1127155
1129770
1130840
1131335
1131336
1131645
1132390
1133140
1133190
1133191
1133738
1134395
1135642
1136446
1136598
1136889
1136922
1136935
1137004
1137194
1137597
1137739
1137749
1137752
1137915
1138291
1138293
1138374
1138681
1139751
1140575
1140577
1140868
1141853
1144524
1144903
1149955
1153108
1153158
1153161
1153238
1160467
1160468
1162197
1162200
1162423
1166847
1173274
1174091
1174701
CVE-2011-2483
CVE-2011-3177
CVE-2015-2924
CVE-2016-0634
CVE-2016-0764
CVE-2016-7543
CVE-2017-1000408
CVE-2017-1000409
CVE-2017-13166
CVE-2017-15670
CVE-2017-15671
CVE-2017-15804
CVE-2017-16997
CVE-2018-1000001
CVE-2018-1000004
CVE-2018-1068
CVE-2018-1122
CVE-2018-1123
CVE-2018-1124
CVE-2018-1125
CVE-2018-1126
CVE-2018-11805
CVE-2018-12126
CVE-2018-12127
CVE-2018-12130
CVE-2018-14647
CVE-2018-20836
CVE-2018-20852
CVE-2018-7566
CVE-2019-10126
CVE-2019-10220
CVE-2019-10638
CVE-2019-10639
CVE-2019-11091
CVE-2019-11477
CVE-2019-11478
CVE-2019-11487
CVE-2019-11487
CVE-2019-11599
CVE-2019-11709
CVE-2019-11711
CVE-2019-11712
CVE-2019-11713
CVE-2019-11715
CVE-2019-11717
CVE-2019-11719
CVE-2019-11729
CVE-2019-11730
CVE-2019-12380
CVE-2019-12456
CVE-2019-12614
CVE-2019-12818
CVE-2019-12819
CVE-2019-13456
CVE-2019-14896
CVE-2019-14897
CVE-2019-16056
CVE-2019-16935
CVE-2019-17133
CVE-2019-17185
CVE-2019-20907
CVE-2019-3813
CVE-2019-3846
CVE-2019-9811
CVE-2019-9947
CVE-2020-14422
CVE-2020-1930
CVE-2020-1931
SUSE-SU-2018:0074-1
SUSE-SU-2018:1031-1
SUSE-SU-2019:0230-1
SUSE-SU-2019:0450-1
SUSE-SU-2019:1235-1
SUSE-SU-2019:1852-1
SUSE-SU-2019:1861-1
SUSE-SU-2020:0204-1
SUSE-SU-2020:0810-1
SUSE-SU-2020:2391-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND Package Information
  • perl-5.26.1-lp150.5 is installed
  • OR perl-base-5.26.1-lp150.5 is installed
  • OR perl-base-32bit-5.26.1-lp150.5 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • libjavascriptcoregtk-4_0-18-2.28.2-lp151.2.18 is installed
  • OR libjavascriptcoregtk-4_0-18-32bit-2.28.2-lp151.2.18 is installed
  • OR libwebkit2gtk-4_0-37-2.28.2-lp151.2.18 is installed
  • OR libwebkit2gtk-4_0-37-32bit-2.28.2-lp151.2.18 is installed
  • OR libwebkit2gtk3-lang-2.28.2-lp151.2.18 is installed
  • OR typelib-1_0-JavaScriptCore-4_0-2.28.2-lp151.2.18 is installed
  • OR typelib-1_0-WebKit2-4_0-2.28.2-lp151.2.18 is installed
  • OR typelib-1_0-WebKit2WebExtension-4_0-2.28.2-lp151.2.18 is installed
  • OR webkit-jsc-4-2.28.2-lp151.2.18 is installed
  • OR webkit2gtk-4_0-injected-bundles-2.28.2-lp151.2.18 is installed
  • OR webkit2gtk3-2.28.2-lp151.2.18 is installed
  • OR webkit2gtk3-devel-2.28.2-lp151.2.18 is installed
  • OR webkit2gtk3-minibrowser-2.28.2-lp151.2.18 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND Package Information
  • glibc-2.22-62.3 is installed
  • OR glibc-32bit-2.22-62.3 is installed
  • OR glibc-devel-2.22-62.3 is installed
  • OR glibc-devel-32bit-2.22-62.3 is installed
  • OR glibc-html-2.22-62.3 is installed
  • OR glibc-i18ndata-2.22-62.3 is installed
  • OR glibc-info-2.22-62.3 is installed
  • OR glibc-locale-2.22-62.3 is installed
  • OR glibc-locale-32bit-2.22-62.3 is installed
  • OR glibc-profile-2.22-62.3 is installed
  • OR glibc-profile-32bit-2.22-62.3 is installed
  • OR nscd-2.22-62.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND Package Information
  • freeradius-server-3.0.3-17.15 is installed
  • OR freeradius-server-doc-3.0.3-17.15 is installed
  • OR freeradius-server-krb5-3.0.3-17.15 is installed
  • OR freeradius-server-ldap-3.0.3-17.15 is installed
  • OR freeradius-server-libs-3.0.3-17.15 is installed
  • OR freeradius-server-mysql-3.0.3-17.15 is installed
  • OR freeradius-server-perl-3.0.3-17.15 is installed
  • OR freeradius-server-postgresql-3.0.3-17.15 is installed
  • OR freeradius-server-python-3.0.3-17.15 is installed
  • OR freeradius-server-sqlite-3.0.3-17.15 is installed
  • OR freeradius-server-utils-3.0.3-17.15 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND Package Information
  • bash-4.3-83.10 is installed
  • OR bash-doc-4.3-83.10 is installed
  • OR libreadline6-6.3-83.10 is installed
  • OR libreadline6-32bit-6.3-83.10 is installed
  • OR readline-doc-6.3-83.10 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND ucode-intel-20190507-13.41 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND Package Information
  • libnm-glib-vpn1-1.0.12-12 is installed
  • OR libnm-glib4-1.0.12-12 is installed
  • OR libnm-util2-1.0.12-12 is installed
  • OR libnm0-1.0.12-12 is installed
  • OR typelib-1_0-NMClient-1_0-1.0.12-12 is installed
  • OR typelib-1_0-NetworkManager-1_0-1.0.12-12 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND Package Information
  • libseccomp-2.4.1-11.3 is installed
  • OR libseccomp2-2.4.1-11.3 is installed
  • OR libseccomp2-32bit-2.4.1-11.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND mailman-2.1.17-3.11 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • ghostscript-9.27-23.28 is installed
  • OR ghostscript-x11-9.27-23.28 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • ImageMagick-6.8.8.1-71.85 is installed
  • OR libMagickCore-6_Q16-1-6.8.8.1-71.85 is installed
  • OR libMagickWand-6_Q16-1-6.8.8.1-71.85 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • giflib-progs-5.0.5-12 is installed
  • OR libgif6-5.0.5-12 is installed
  • OR libgif6-32bit-5.0.5-12 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND Package Information
  • kernel-default-4.4.180-94.100 is installed
  • OR kernel-default-base-4.4.180-94.100 is installed
  • OR kernel-default-devel-4.4.180-94.100 is installed
  • OR kernel-devel-4.4.180-94.100 is installed
  • OR kernel-macros-4.4.180-94.100 is installed
  • OR kernel-source-4.4.180-94.100 is installed
  • OR kernel-syms-4.4.180-94.100 is installed
  • OR kgraft-patch-4_4_180-94_100-default-1-4.3 is installed
  • OR kgraft-patch-SLE12-SP3_Update_27-1-4.3 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND Package Information
  • libmariadb3-3.0.3-3.3 is installed
  • OR mariadb-10.2.15-4.3 is installed
  • OR mariadb-client-10.2.15-4.3 is installed
  • OR mariadb-connector-c-3.0.3-3.3 is installed
  • OR mariadb-errormessages-10.2.15-4.3 is installed
  • OR mariadb-galera-10.2.15-4.3 is installed
  • OR mariadb-tools-10.2.15-4.3 is installed
  • OR xtrabackup-2.4.10-4.3 is installed
  • BACK