SUSE-SU-2020:0832-1

Advisory lineage Upstream: 3 Downstream: 0
Published: 31 Mar 2020, 14:16
Last modified:04 Feb 2026, 02:46

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

31 Mar 2020, 14:16
Published
Vulnerability first disclosed
04 Feb 2026, 02:46
Last Modified
Vulnerability information updated

Description

Security update for glibc This update for glibc fixes the following issues: - CVE-2020-1752: Fixed a use after free in glob which could have allowed a local attacker to create a specially crafted path that, when processed by the glob function, could potentially have led to arbitrary code execution (bsc#1167631). - CVE-2020-1751: Fixed an array overflow in backtrace for PowerPC (bsc#1158996). - CVE-2020-10029: Fixed a stack buffer overflow during range reduction (bsc#1165784). - Use 'posix_spawn' on popen preventing crash caused by 'subprocess'. (bsc#1149332, BZ #22834) - Fix handling of needles crossing a page, preventing incorrect results to return during the cross page boundary search. (bsc#1157893, BZ #25226)

Affected Systems

  • suseglibc&distro=SUSE Linux Enterprise Server 12 SP4

    < 2.22-100.21.5

  • suseglibc&distro=SUSE Linux Enterprise Server 12 SP5

    < 2.22-100.21.5

  • suseglibc&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP4

    < 2.22-100.21.5

  • suseglibc&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP5

    < 2.22-100.21.5

  • suseglibc&distro=SUSE Linux Enterprise Software Development Kit 12 SP4

    < 2.22-100.21.5

  • suseglibc&distro=SUSE Linux Enterprise Software Development Kit 12 SP5

    < 2.22-100.21.5

References (9)