VYPR

rpm package

suse/glibc&distro=SUSE Linux Enterprise Desktop 12 SP4

pkg:rpm/suse/glibc&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4

Vulnerabilities (4)

  • CVE-2019-9169Feb 26, 2019
    affected < 2.22-100.8.1fixed 2.22-100.8.1

    In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-insensitive regular-expression match.

  • CVE-2009-5155Feb 26, 2019
    affected < 2.22-100.8.1fixed 2.22-100.8.1

    In the GNU C Library (aka glibc or libc6) before 2.28, parse_reg_exp in posix/regcomp.c misparses alternatives, which allows attackers to cause a denial of service (assertion failure and application exit) or trigger an incorrect result by attempting a regular-expression match.

  • CVE-2016-10739Jan 21, 2019
    affected < 2.22-100.8.1fixed 2.22-100.8.1

    In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters, which could lead applications to incorrectly assume that it had parsed a valid string

  • CVE-2015-5180HigJun 27, 2017
    affected < 2.22-100.15.4fixed 2.22-100.15.4

    res_query in libresolv in glibc before 2.25 allows remote attackers to cause a denial of service (NULL pointer dereference and process crash).