SUSE: 2019:1958-1 moderate: glibc
Summary
This update for glibc fixes the following issues: Security issues fixed: - CVE-2019-9169: Fixed a heap-based buffer over-read via an attempted case-insensitive regular-expression match (bsc#1127308). - CVE-2009-5155: Fixed a denial of service in parse_reg_exp() (bsc#1127223). Non-security issues fixed: - Added cfi information for start routines in order to stop unwinding on S390 (bsc#1128574). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2019-1958=1 - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2019-1958=1 - SUSE Linux Enterprise Server for SAP 12-SP3: zypper in -t patch SUSE-SLE-SAP-12-SP3-2019-1958=1 - SUSE Linux Enterprise Server for SAP 12-SP2: ...
Read the Full AdvisoryReferences
#1127223 #1127308 #1128574
Cross- CVE-2009-5155 CVE-2019-9169
Affected Products:
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud 7
SUSE Linux Enterprise Server for SAP 12-SP3
SUSE Linux Enterprise Server for SAP 12-SP2
SUSE Linux Enterprise Server 12-SP3-LTSS
SUSE Linux Enterprise Server 12-SP2-LTSS
SUSE Linux Enterprise Server 12-SP2-BCL
SUSE Enterprise Storage 5
SUSE Enterprise Storage 4
SUSE CaaS Platform 3.0
https://www.suse.com/security/cve/CVE-2009-5155.html
https://www.suse.com/security/cve/CVE-2019-9169.html
https://bugzilla.suse.com/1127223
https://bugzilla.suse.com/1127308
https://bugzilla.suse.com/1128574