SUSE-SU-2018:2185-1
Advisory lineage Upstream: 5 Downstream: 0
Published: 03 Aug 2018, 13:49
Last modified:04 Feb 2026, 03:51
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
03 Aug 2018, 13:49
Published
Vulnerability first disclosed
04 Feb 2026, 03:51
Last Modified
Vulnerability information updated
Description
Security update for glibc This update for glibc fixes the following issues: Security issues fixed: - CVE-2017-15804: Fix buffer overflow during unescaping of user names in the glob function in glob.c (bsc#1064580). - CVE-2017-15670: Fix buffer overflow in glob with GLOB_TILDE (bsc#1064583). - CVE-2017-15671: Fix memory leak in glob with GLOB_TILDE (bsc#1064569). - CVE-2018-11236: Fix 32bit arch integer overflow in stdlib/canonicalize.c when processing very long pathname arguments (bsc#1094161). - CVE-2017-12132: Reduce advertised EDNS0 buffer size to guard against fragmentation attacks (bsc#1051791).
Affected Systems
- suse•glibc&distro=SUSE Linux Enterprise Server 12 SP1-LTSS
< 2.19-40.16.950
- suse•glibc&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP1
< 2.19-40.16.950
References (11)
- https://www.suse.com/support/update/announcement/2018/suse-su-20182185-1/
- https://bugzilla.suse.com/1051791
- https://bugzilla.suse.com/1064569
- https://bugzilla.suse.com/1064580
- https://bugzilla.suse.com/1064583
- https://bugzilla.suse.com/1094161
- https://www.suse.com/security/cve/CVE-2017-12132
- https://www.suse.com/security/cve/CVE-2017-15670
- https://www.suse.com/security/cve/CVE-2017-15671
- https://www.suse.com/security/cve/CVE-2017-15804
- https://www.suse.com/security/cve/CVE-2018-11236