{"affected":[{"ecosystem_specific":{"binaries":[{"glibc-html":"2.11.3-17.87.3","glibc-info":"2.11.3-17.87.3"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Software Development Kit 11 SP3","name":"glibc","purl":"pkg:rpm/suse/glibc&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.11.3-17.87.3"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"glibc-html":"2.11.3-17.87.3","glibc-info":"2.11.3-17.87.3"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Software Development Kit 11 SP4","name":"glibc","purl":"pkg:rpm/suse/glibc&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.11.3-17.87.3"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"glibc":"2.11.3-17.87.3","glibc-32bit":"2.11.3-17.87.3","glibc-devel":"2.11.3-17.87.3","glibc-devel-32bit":"2.11.3-17.87.3","glibc-i18ndata":"2.11.3-17.87.3","glibc-locale":"2.11.3-17.87.3","glibc-locale-32bit":"2.11.3-17.87.3","nscd":"2.11.3-17.87.3"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 11 SP3","name":"glibc","purl":"pkg:rpm/suse/glibc&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.11.3-17.87.3"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"glibc":"2.11.3-17.87.3","glibc-32bit":"2.11.3-17.87.3","glibc-devel":"2.11.3-17.87.3","glibc-devel-32bit":"2.11.3-17.87.3","glibc-i18ndata":"2.11.3-17.87.3","glibc-locale":"2.11.3-17.87.3","glibc-locale-32bit":"2.11.3-17.87.3","nscd":"2.11.3-17.87.3"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 11 SP4","name":"glibc","purl":"pkg:rpm/suse/glibc&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.11.3-17.87.3"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"glibc":"2.11.3-17.87.3","glibc-32bit":"2.11.3-17.87.3","glibc-devel":"2.11.3-17.87.3","glibc-devel-32bit":"2.11.3-17.87.3","glibc-html":"2.11.3-17.87.3","glibc-i18ndata":"2.11.3-17.87.3","glibc-info":"2.11.3-17.87.3","glibc-locale":"2.11.3-17.87.3","glibc-locale-32bit":"2.11.3-17.87.3","glibc-locale-x86":"2.11.3-17.87.3","glibc-profile":"2.11.3-17.87.3","glibc-profile-32bit":"2.11.3-17.87.3","glibc-profile-x86":"2.11.3-17.87.3","glibc-x86":"2.11.3-17.87.3","nscd":"2.11.3-17.87.3"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP3","name":"glibc","purl":"pkg:rpm/suse/glibc&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.11.3-17.87.3"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"glibc":"2.11.3-17.87.3","glibc-32bit":"2.11.3-17.87.3","glibc-devel":"2.11.3-17.87.3","glibc-devel-32bit":"2.11.3-17.87.3","glibc-html":"2.11.3-17.87.3","glibc-i18ndata":"2.11.3-17.87.3","glibc-info":"2.11.3-17.87.3","glibc-locale":"2.11.3-17.87.3","glibc-locale-32bit":"2.11.3-17.87.3","glibc-locale-x86":"2.11.3-17.87.3","glibc-profile":"2.11.3-17.87.3","glibc-profile-32bit":"2.11.3-17.87.3","glibc-profile-x86":"2.11.3-17.87.3","glibc-x86":"2.11.3-17.87.3","nscd":"2.11.3-17.87.3"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP3-TERADATA","name":"glibc","purl":"pkg:rpm/suse/glibc&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-TERADATA"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.11.3-17.87.3"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"glibc":"2.11.3-17.87.3","glibc-32bit":"2.11.3-17.87.3","glibc-devel":"2.11.3-17.87.3","glibc-devel-32bit":"2.11.3-17.87.3","glibc-html":"2.11.3-17.87.3","glibc-i18ndata":"2.11.3-17.87.3","glibc-info":"2.11.3-17.87.3","glibc-locale":"2.11.3-17.87.3","glibc-locale-32bit":"2.11.3-17.87.3","glibc-locale-x86":"2.11.3-17.87.3","glibc-profile":"2.11.3-17.87.3","glibc-profile-32bit":"2.11.3-17.87.3","glibc-profile-x86":"2.11.3-17.87.3","glibc-x86":"2.11.3-17.87.3","nscd":"2.11.3-17.87.3"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 11 SP3","name":"glibc","purl":"pkg:rpm/suse/glibc&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.11.3-17.87.3"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"glibc":"2.11.3-17.87.3","glibc-32bit":"2.11.3-17.87.3","glibc-devel":"2.11.3-17.87.3","glibc-devel-32bit":"2.11.3-17.87.3","glibc-html":"2.11.3-17.87.3","glibc-i18ndata":"2.11.3-17.87.3","glibc-info":"2.11.3-17.87.3","glibc-locale":"2.11.3-17.87.3","glibc-locale-32bit":"2.11.3-17.87.3","glibc-locale-x86":"2.11.3-17.87.3","glibc-profile":"2.11.3-17.87.3","glibc-profile-32bit":"2.11.3-17.87.3","glibc-profile-x86":"2.11.3-17.87.3","glibc-x86":"2.11.3-17.87.3","nscd":"2.11.3-17.87.3"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP4","name":"glibc","purl":"pkg:rpm/suse/glibc&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.11.3-17.87.3"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"glibc":"2.11.3-17.87.3","glibc-32bit":"2.11.3-17.87.3","glibc-devel":"2.11.3-17.87.3","glibc-devel-32bit":"2.11.3-17.87.3","glibc-html":"2.11.3-17.87.3","glibc-i18ndata":"2.11.3-17.87.3","glibc-info":"2.11.3-17.87.3","glibc-locale":"2.11.3-17.87.3","glibc-locale-32bit":"2.11.3-17.87.3","glibc-locale-x86":"2.11.3-17.87.3","glibc-profile":"2.11.3-17.87.3","glibc-profile-32bit":"2.11.3-17.87.3","glibc-profile-x86":"2.11.3-17.87.3","glibc-x86":"2.11.3-17.87.3","nscd":"2.11.3-17.87.3"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 11 SP4","name":"glibc","purl":"pkg:rpm/suse/glibc&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.11.3-17.87.3"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for glibc provides fixes for security and non-security issues.\n\nThese security issues have been fixed:\n\n- CVE-2015-1781: Buffer length after padding in resolv/nss_dns/dns-host.c. (bsc#927080)\n- CVE-2013-2207: pt_chown did not properly check permissions for tty files, which allowed\n  local users to change the permission on the files and obtain access to arbitrary\n  pseudo-terminals by leveraging a FUSE file system. (bsc#830257)\n- CVE-2014-8121: DB_LOOKUP in the Name Service Switch (NSS) did not properly check if a\n  file is open, which allowed remote attackers to cause a denial of service (infinite loop)\n  by performing a look-up while the database is iterated over the database, which triggers\n  the file pointer to be reset. (bsc#918187)\n- Fix read past end of pattern in fnmatch. (bsc#920338)\n\nThese non-security issues have been fixed:\n\n- Fix locking in _IO_flush_all_lockp() to prevent deadlocks in applications. (bsc#851280)\n- Record TTL also for DNS PTR queries. (bsc#928723)\n- Fix invalid free in ld.so. (bsc#932059)\n- Make PowerPC64 default to non-executable stack. (bsc#933770)\n- Fix floating point exceptions in some circumstances with exp() and friends. (bsc#933903)\n- Fix bad TEXTREL in glibc.i686. (bsc#935286)\n  ","id":"SUSE-SU-2015:1424-1","modified":"2015-07-31T18:02:04Z","published":"2015-07-31T18:02:04Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2015/suse-su-20151424-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/830257"},{"type":"REPORT","url":"https://bugzilla.suse.com/851280"},{"type":"REPORT","url":"https://bugzilla.suse.com/918187"},{"type":"REPORT","url":"https://bugzilla.suse.com/920338"},{"type":"REPORT","url":"https://bugzilla.suse.com/927080"},{"type":"REPORT","url":"https://bugzilla.suse.com/928723"},{"type":"REPORT","url":"https://bugzilla.suse.com/932059"},{"type":"REPORT","url":"https://bugzilla.suse.com/933770"},{"type":"REPORT","url":"https://bugzilla.suse.com/933903"},{"type":"REPORT","url":"https://bugzilla.suse.com/935286"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2013-2207"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2014-8121"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-1781"}],"related":["CVE-2013-2207","CVE-2014-8121","CVE-2015-1781"],"summary":"Security update for glibc","upstream":["CVE-2013-2207","CVE-2014-8121","CVE-2015-1781"]}