SUSE-SU-2019:1102-1
Dashboard / Vulnerabilities / SUSE-SU-2019:1102-1
SUSE-SU-2019:1102-1
Summary: Security update for glibc
Details: This update for glibc fixes the following issues: Security issues fixed: - CVE-2019-9169: regex: fix read overrun (bsc#1127308, BZ #24114) - CVE-2016-10739: Fully parse IPv4 address strings (bsc#1122729, BZ #20018) - CVE-2009-5155: ERE '0|()0|\1|0' causes regexec undefined behavior (bsc#1127223, BZ #18986) Non-security issues fixed: - Enable TLE only if GLIBC_ELISION_ENABLE=yes is defined (bsc#1131994, fate#322271) - Add more checks for valid ld.so.cache file (bsc#1110661, BZ #18093) - Added cfi information for start routines in order to stop unwinding (bsc#1128574) - ja_JP locale: Add entry for the new Japanese era (bsc#1100396, fate#325570, BZ #22964)
References: https://www.suse.com/support/update/announcement/2019/suse-su-20191102-1/, https://bugzilla.suse.com/1100396, https://bugzilla.suse.com/1110661, https://bugzilla.suse.com/1122729, https://bugzilla.suse.com/1127223, https://bugzilla.suse.com/1127308, https://bugzilla.suse.com/1128574, https://bugzilla.suse.com/1131994, https://www.suse.com/security/cve/CVE-2009-5155, https://www.suse.com/security/cve/CVE-2016-10739, https://www.suse.com/security/cve/CVE-2019-9169
Affected packages
Package
Name: glibc
Purl: pkg:rpm/suse/glibc&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
