{"affected":[{"ecosystem_specific":{"binaries":[{"glibc":"2.22-62.13.2","glibc-32bit":"2.22-62.13.2","glibc-devel":"2.22-62.13.2","glibc-devel-32bit":"2.22-62.13.2","glibc-html":"2.22-62.13.2","glibc-i18ndata":"2.22-62.13.2","glibc-info":"2.22-62.13.2","glibc-locale":"2.22-62.13.2","glibc-locale-32bit":"2.22-62.13.2","glibc-profile":"2.22-62.13.2","glibc-profile-32bit":"2.22-62.13.2","nscd":"2.22-62.13.2"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP2-BCL","name":"glibc","purl":"pkg:rpm/suse/glibc&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCL"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.22-62.13.2"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"\n  \nThis update for glibc fixes the following issues:\n\n- CVE-2017-18269: Fix SSE2 memmove issue when crossing 2GB boundary (bsc#1094150)\n- CVE-2018-11236: Fix overflow in path length computation (bsc#1094161)\n- CVE-2018-11237: Don't write beyond buffer destination in __mempcpy_avx512_no_vzeroupper (bsc#1094154)\n\nNon security bugs fixed:\n\n- Fix crash in resolver on memory allocation failure (bsc#1086690)\n\n","id":"SUSE-SU-2018:1562-2","modified":"2018-10-18T12:46:04Z","published":"2018-10-18T12:46:04Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2018/suse-su-20181562-2/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1086690"},{"type":"REPORT","url":"https://bugzilla.suse.com/1094150"},{"type":"REPORT","url":"https://bugzilla.suse.com/1094154"},{"type":"REPORT","url":"https://bugzilla.suse.com/1094161"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-18269"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-11236"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-11237"}],"related":["CVE-2017-18269","CVE-2018-11236","CVE-2018-11237"],"summary":"Security update for glibc","upstream":["CVE-2017-18269","CVE-2018-11236","CVE-2018-11237"]}