{"affected":[{"ecosystem_specific":{"binaries":[{"glibc":"2.22-62.3.4","glibc-32bit":"2.22-62.3.4","glibc-devel":"2.22-62.3.4","glibc-devel-32bit":"2.22-62.3.4","glibc-i18ndata":"2.22-62.3.4","glibc-locale":"2.22-62.3.4","glibc-locale-32bit":"2.22-62.3.4","nscd":"2.22-62.3.4"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 12 SP2","name":"glibc","purl":"pkg:rpm/suse/glibc&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.22-62.3.4"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"glibc":"2.22-62.3.4","glibc-32bit":"2.22-62.3.4","glibc-devel":"2.22-62.3.4","glibc-devel-32bit":"2.22-62.3.4","glibc-i18ndata":"2.22-62.3.4","glibc-locale":"2.22-62.3.4","glibc-locale-32bit":"2.22-62.3.4","nscd":"2.22-62.3.4"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 12 SP3","name":"glibc","purl":"pkg:rpm/suse/glibc&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.22-62.3.4"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"glibc":"2.22-62.3.4","glibc-devel":"2.22-62.3.4","glibc-html":"2.22-62.3.4","glibc-i18ndata":"2.22-62.3.4","glibc-info":"2.22-62.3.4","glibc-locale":"2.22-62.3.4","glibc-profile":"2.22-62.3.4","nscd":"2.22-62.3.4"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for Raspberry Pi 12 SP2","name":"glibc","purl":"pkg:rpm/suse/glibc&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.22-62.3.4"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"glibc-devel-static":"2.22-62.3.4","glibc-info":"2.22-62.3.4"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP2","name":"glibc","purl":"pkg:rpm/suse/glibc&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.22-62.3.4"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"glibc-devel-static":"2.22-62.3.4","glibc-info":"2.22-62.3.4"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP3","name":"glibc","purl":"pkg:rpm/suse/glibc&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.22-62.3.4"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"glibc":"2.22-62.3.4","glibc-32bit":"2.22-62.3.4","glibc-devel":"2.22-62.3.4","glibc-devel-32bit":"2.22-62.3.4","glibc-html":"2.22-62.3.4","glibc-i18ndata":"2.22-62.3.4","glibc-info":"2.22-62.3.4","glibc-locale":"2.22-62.3.4","glibc-locale-32bit":"2.22-62.3.4","glibc-profile":"2.22-62.3.4","glibc-profile-32bit":"2.22-62.3.4","nscd":"2.22-62.3.4"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP2","name":"glibc","purl":"pkg:rpm/suse/glibc&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.22-62.3.4"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"glibc":"2.22-62.3.4","glibc-32bit":"2.22-62.3.4","glibc-devel":"2.22-62.3.4","glibc-devel-32bit":"2.22-62.3.4","glibc-html":"2.22-62.3.4","glibc-i18ndata":"2.22-62.3.4","glibc-info":"2.22-62.3.4","glibc-locale":"2.22-62.3.4","glibc-locale-32bit":"2.22-62.3.4","glibc-profile":"2.22-62.3.4","glibc-profile-32bit":"2.22-62.3.4","nscd":"2.22-62.3.4"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP2","name":"glibc","purl":"pkg:rpm/suse/glibc&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.22-62.3.4"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"glibc":"2.22-62.3.4","glibc-32bit":"2.22-62.3.4","glibc-devel":"2.22-62.3.4","glibc-devel-32bit":"2.22-62.3.4","glibc-html":"2.22-62.3.4","glibc-i18ndata":"2.22-62.3.4","glibc-info":"2.22-62.3.4","glibc-locale":"2.22-62.3.4","glibc-locale-32bit":"2.22-62.3.4","glibc-profile":"2.22-62.3.4","glibc-profile-32bit":"2.22-62.3.4","nscd":"2.22-62.3.4"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP3","name":"glibc","purl":"pkg:rpm/suse/glibc&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.22-62.3.4"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"glibc":"2.22-62.3.4","glibc-32bit":"2.22-62.3.4","glibc-devel":"2.22-62.3.4","glibc-devel-32bit":"2.22-62.3.4","glibc-html":"2.22-62.3.4","glibc-i18ndata":"2.22-62.3.4","glibc-info":"2.22-62.3.4","glibc-locale":"2.22-62.3.4","glibc-locale-32bit":"2.22-62.3.4","glibc-profile":"2.22-62.3.4","glibc-profile-32bit":"2.22-62.3.4","nscd":"2.22-62.3.4"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP3","name":"glibc","purl":"pkg:rpm/suse/glibc&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.22-62.3.4"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for glibc fixes the following issues:\n\n- A privilege escalation bug in the realpath() function has been fixed.\n  [CVE-2018-1000001, bsc#1074293]\n\n- A memory leak and a buffer overflow in the dynamic ELF loader has been fixed.\n  [CVE-2017-1000408, CVE-2017-1000409, bsc#1071319]\n\n- An issue in the code handling RPATHs was fixed that could have been exploited\n  by an attacker to execute code loaded from arbitrary libraries.\n  [CVE-2017-16997, bsc#1073231]\n\n- A potential crash caused by a use-after-free bug in pthread_create() has been\n  fixed. [bsc#1053188]\n\n- A bug that prevented users to build shared objects which use the optimized\n  libmvec.so API has been fixed. [bsc#1070905]\n\n- A memory leak in the glob() function has been fixed. [CVE-2017-15670,\n  CVE-2017-15671, CVE-2017-15804, bsc#1064569, bsc#1064580, bsc#1064583]\n\n- A bug that would lose the syscall error code value in case of crashes has\n  been fixed. [bsc#1063675]\n","id":"SUSE-SU-2018:0074-1","modified":"2018-01-12T08:46:15Z","published":"2018-01-12T08:46:15Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2018/suse-su-20180074-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1051042"},{"type":"REPORT","url":"https://bugzilla.suse.com/1053188"},{"type":"REPORT","url":"https://bugzilla.suse.com/1063675"},{"type":"REPORT","url":"https://bugzilla.suse.com/1064569"},{"type":"REPORT","url":"https://bugzilla.suse.com/1064580"},{"type":"REPORT","url":"https://bugzilla.suse.com/1064583"},{"type":"REPORT","url":"https://bugzilla.suse.com/1070905"},{"type":"REPORT","url":"https://bugzilla.suse.com/1071319"},{"type":"REPORT","url":"https://bugzilla.suse.com/1073231"},{"type":"REPORT","url":"https://bugzilla.suse.com/1074293"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-1000408"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-1000409"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-15670"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-15671"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-15804"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-16997"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-1000001"}],"related":["CVE-2017-1000408","CVE-2017-1000409","CVE-2017-15670","CVE-2017-15671","CVE-2017-15804","CVE-2017-16997","CVE-2018-1000001"],"summary":"Security update for glibc","upstream":["CVE-2017-1000408","CVE-2017-1000409","CVE-2017-15670","CVE-2017-15671","CVE-2017-15804","CVE-2017-16997","CVE-2018-1000001"]}