SUSE-SU-2016:1721-1
Dashboard / Vulnerabilities / SUSE-SU-2016:1721-1
SUSE-SU-2016:1721-1
Summary: Security update for glibc
Details: This update for glibc provides the following fixes: - Increase DTV_SURPLUS limit. (bsc#968787) - Do not copy d_name field of struct dirent. (CVE-2016-1234, bsc#969727) - Fix memory leak in _nss_dns_gethostbyname4_r. (bsc#973010) - Fix stack overflow in _nss_dns_getnetbyname_r. (CVE-2016-3075, bsc#973164) - Fix malloc performance regression from SLE 11. (bsc#975930) - Fix getaddrinfo stack overflow in hostent conversion. (CVE-2016-3706, bsc#980483) - Do not use alloca in clntudp_call (CVE-2016-4429, bsc#980854)
References: https://www.suse.com/support/update/announcement/2016/suse-su-20161721-1/, https://bugzilla.suse.com/968787, https://bugzilla.suse.com/969727, https://bugzilla.suse.com/973010, https://bugzilla.suse.com/973164, https://bugzilla.suse.com/975930, https://bugzilla.suse.com/980483, https://bugzilla.suse.com/980854, https://www.suse.com/security/cve/CVE-2016-1234, https://www.suse.com/security/cve/CVE-2016-3075, https://www.suse.com/security/cve/CVE-2016-3706, https://www.suse.com/security/cve/CVE-2016-4429
Affected packages
Package
Name: glibc
Purl: pkg:rpm/suse/glibc&distro=SUSE%20Linux%20Enterprise%20Desktop%2012
Affected ranges
Type: ECOSYSTEM
Events:
