SUSE-RU-2012:0572-1: Recommended update for glibc

sle-updates at lists.suse.com sle-updates at lists.suse.com
Mon Apr 30 14:08:12 MDT 2012


   SUSE Recommended Update: Recommended update for glibc
______________________________________________________________________________

Announcement ID:    SUSE-RU-2012:0572-1
Rating:             low
References:         #741345 #743689 #744996 #745658 #746824 #747768 
                    
Affected Products:
                    SUSE Linux Enterprise Software Development Kit 11 SP2
                    SUSE Linux Enterprise Server 11 SP2 for VMware
                    SUSE Linux Enterprise Server 11 SP2
                    SUSE Linux Enterprise Desktop 11 SP2
______________________________________________________________________________

   An update that solves one vulnerability and has 5 fixes is
   now available.

Description:


   This update for glibc includes the following changes:

   * Fix sed not parsing correctly double-byte Japanese
   characters.
   * Avoid unsupported file modification in package
   glibc-locale.
   * Remove references to __memmove_chk_ssse3 in static
   libc.
   * Fix format string protection bypass via "nargs"
   integer overflow.
   * Fix a vi_VN.tcvn locale problem.
   * Fix segfault in libpthread on heavy thread usage.

   In addition, the following minor security fix is also
   included:

   * Fix an integer overflow flaw in the format string
   protection mechanism offered by FORTIFY_SOURCE.
   (CVE-2012-0864
   <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0864
   > )


Patch Instructions:

   To install this SUSE Recommended Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - SUSE Linux Enterprise Software Development Kit 11 SP2:

      zypper in -t patch sdksp2-glibc-6135

   - SUSE Linux Enterprise Server 11 SP2 for VMware:

      zypper in -t patch slessp2-glibc-6135

   - SUSE Linux Enterprise Server 11 SP2:

      zypper in -t patch slessp2-glibc-6135

   - SUSE Linux Enterprise Desktop 11 SP2:

      zypper in -t patch sledsp2-glibc-6135

   To bring your system up-to-date, use "zypper patch".


Package List:

   - SUSE Linux Enterprise Software Development Kit 11 SP2 (i586 x86_64):

      glibc-html-2.11.3-17.35.4
      glibc-info-2.11.3-17.35.4

   - SUSE Linux Enterprise Server 11 SP2 for VMware (i586 i686 x86_64):

      glibc-2.11.3-17.35.4
      glibc-devel-2.11.3-17.35.4

   - SUSE Linux Enterprise Server 11 SP2 for VMware (i586 x86_64):

      glibc-html-2.11.3-17.35.4
      glibc-i18ndata-2.11.3-17.35.4
      glibc-info-2.11.3-17.35.4
      glibc-locale-2.11.3-17.35.4
      glibc-profile-2.11.3-17.35.4
      nscd-2.11.3-17.35.4

   - SUSE Linux Enterprise Server 11 SP2 for VMware (x86_64):

      glibc-32bit-2.11.3-17.35.4
      glibc-devel-32bit-2.11.3-17.35.4
      glibc-locale-32bit-2.11.3-17.35.4
      glibc-profile-32bit-2.11.3-17.35.4

   - SUSE Linux Enterprise Server 11 SP2 (i586 i686 ia64 ppc64 s390x x86_64):

      glibc-2.11.3-17.35.4
      glibc-devel-2.11.3-17.35.4

   - SUSE Linux Enterprise Server 11 SP2 (i586 ia64 ppc64 s390x x86_64):

      glibc-html-2.11.3-17.35.4
      glibc-i18ndata-2.11.3-17.35.4
      glibc-info-2.11.3-17.35.4
      glibc-locale-2.11.3-17.35.4
      glibc-profile-2.11.3-17.35.4
      nscd-2.11.3-17.35.4

   - SUSE Linux Enterprise Server 11 SP2 (ppc64 s390x x86_64):

      glibc-32bit-2.11.3-17.35.4
      glibc-devel-32bit-2.11.3-17.35.4
      glibc-locale-32bit-2.11.3-17.35.4
      glibc-profile-32bit-2.11.3-17.35.4

   - SUSE Linux Enterprise Server 11 SP2 (ia64):

      glibc-locale-x86-2.11.3-17.35.4
      glibc-profile-x86-2.11.3-17.35.4
      glibc-x86-2.11.3-17.35.4

   - SUSE Linux Enterprise Desktop 11 SP2 (i586 i686 x86_64):

      glibc-2.11.3-17.35.4
      glibc-devel-2.11.3-17.35.4

   - SUSE Linux Enterprise Desktop 11 SP2 (i586 x86_64):

      glibc-i18ndata-2.11.3-17.35.4
      glibc-locale-2.11.3-17.35.4
      nscd-2.11.3-17.35.4

   - SUSE Linux Enterprise Desktop 11 SP2 (x86_64):

      glibc-32bit-2.11.3-17.35.4
      glibc-devel-32bit-2.11.3-17.35.4
      glibc-locale-32bit-2.11.3-17.35.4


References:

   http://support.novell.com/security/cve/CVE-2012-0864.html
   https://bugzilla.novell.com/741345
   https://bugzilla.novell.com/743689
   https://bugzilla.novell.com/744996
   https://bugzilla.novell.com/745658
   https://bugzilla.novell.com/746824
   https://bugzilla.novell.com/747768
   http://download.novell.com/patch/finder/?keywords=a417242ac1889d7c5b2cd943089c2e82



More information about the sle-updates mailing list