VYPR

rpm package

opensuse/glibc&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/glibc&distro=openSUSE%20Tumbleweed

Vulnerabilities (104)

  • CVE-2021-27645LowFeb 24, 2021
    affected < 2.34-1.2fixed 2.34-1.2

    The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, when processing a request for netgroup lookup, may crash due to a double-free, potentially resulting in degraded service or Denial of Service on the local system. This is related to

  • CVE-2021-3326HigJan 27, 2021
    affected < 2.34-1.2fixed 2.34-1.2

    The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service.

  • CVE-2019-25013MedJan 4, 2021
    affected < 2.34-1.2fixed 2.34-1.2

    The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input sequences in the EUC-KR encoding, may have a buffer over-read.

  • CVE-2020-29573HigDec 6, 2020
    affected < 2.34-1.2fixed 2.34-1.2

    sysdeps/i386/ldbl2mpn.c in the GNU C Library (aka glibc or libc6) before 2.23 on x86 targets has a stack-based buffer overflow if the input to any of the printf family of functions is an 80-bit long double with a non-canonical bit pattern, as seen when passing a \x00\x04\x00\x00\

  • CVE-2020-29562MedDec 4, 2020
    affected < 2.34-1.2fixed 2.34-1.2

    The iconv function in the GNU C Library (aka glibc or libc6) 2.30 to 2.32, when converting UCS4 text containing an irreversible character, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service.

  • CVE-2020-1752HigApr 30, 2020
    affected < 2.34-1.2fixed 2.34-1.2

    A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by this issue. A local attacker could exploit this flaw by cre

  • CVE-2020-1751MedApr 17, 2020
    affected < 2.38-6.1fixed 2.38-6.1

    An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtrace function did not properly check the array bounds when storing the frame address, resulting in a denial of service or potential code executi

  • CVE-2020-6096HigApr 1, 2020
    affected < 2.34-1.2fixed 2.34-1.2

    An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) with a negative value for the 'num' parameter results in a signed comparison vulnerabil

  • CVE-2020-10029MedMar 4, 2020
    affected < 2.34-1.2fixed 2.34-1.2

    The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input to an 80-bit long double function contains a non-canonical bit pattern, a seen when passing a 0x5d414141414141410000 value to sinl on x86 targets. This is relat

  • CVE-2019-19126LowNov 19, 2019
    affected < 2.34-1.2fixed 2.34-1.2

    On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to restrict the possible mapping addresses for loaded libraries a

  • CVE-2019-9169CriFeb 26, 2019
    affected < 2.34-1.2fixed 2.34-1.2

    In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-insensitive regular-expression match.

  • CVE-2009-5155HigFeb 26, 2019
    affected < 2.34-1.2fixed 2.34-1.2

    In the GNU C Library (aka glibc or libc6) before 2.28, parse_reg_exp in posix/regcomp.c misparses alternatives, which allows attackers to cause a denial of service (assertion failure and application exit) or trigger an incorrect result by attempting a regular-expression match.

  • CVE-2019-7309MedFeb 3, 2019
    affected < 2.34-1.2fixed 2.34-1.2

    In the GNU C Library (aka glibc or libc6) through 2.29, the memcmp function for the x32 architecture can incorrectly return zero (indicating that the inputs are equal) because the RDX most significant bit is mishandled.

  • CVE-2016-10739MedJan 21, 2019
    affected < 2.34-1.2fixed 2.34-1.2

    In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters, which could lead applications to incorrectly assume that it had parsed a valid string

  • CVE-2018-19591HigDec 4, 2018
    affected < 2.34-1.2fixed 2.34-1.2

    In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to the if_nametoindex() function.

  • CVE-2018-11237HigMay 18, 2018
    affected < 2.34-1.2fixed 2.34-1.2

    An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier may write data beyond the target buffer, leading to a buffer overflow in __mempcpy_avx512_no_vzeroupper.

  • CVE-2018-11236CriMay 18, 2018
    affected < 2.34-1.2fixed 2.34-1.2

    stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures, leading to a stack-based buffer overflow and, potentially, arbitra

  • CVE-2017-18269CriMay 18, 2018
    affected < 2.34-1.2fixed 2.34-1.2

    An SSE2-optimized memmove implementation for i386 in sysdeps/i386/i686/multiarch/memcpy-sse2-unaligned.S in the GNU C Library (aka glibc or libc6) 2.21 through 2.27 does not correctly perform the overlapping memory check if the source memory range spans the middle of the address

  • CVE-2018-6485CriFeb 1, 2018
    affected < 2.34-1.2fixed 2.34-1.2

    An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to return a pointer to a heap area that is too small, potentially leading to heap corruption.

  • CVE-2017-1000408HigFeb 1, 2018
    affected < 2.34-1.2fixed 2.34-1.2

    A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366.

Page 3 of 6