{"affected":[{"ecosystem_specific":{"binaries":[{"glibc":"2.26-lp152.26.6.1","glibc-32bit":"2.26-lp152.26.6.1","glibc-devel":"2.26-lp152.26.6.1","glibc-devel-32bit":"2.26-lp152.26.6.1","glibc-devel-static":"2.26-lp152.26.6.1","glibc-devel-static-32bit":"2.26-lp152.26.6.1","glibc-extra":"2.26-lp152.26.6.1","glibc-html":"2.26-lp152.26.6.1","glibc-i18ndata":"2.26-lp152.26.6.1","glibc-info":"2.26-lp152.26.6.1","glibc-locale":"2.26-lp152.26.6.1","glibc-locale-base":"2.26-lp152.26.6.1","glibc-locale-base-32bit":"2.26-lp152.26.6.1","glibc-profile":"2.26-lp152.26.6.1","glibc-profile-32bit":"2.26-lp152.26.6.1","glibc-utils":"2.26-lp152.26.6.1","glibc-utils-32bit":"2.26-lp152.26.6.1","nscd":"2.26-lp152.26.6.1"}]},"package":{"ecosystem":"openSUSE:Leap 15.2","name":"glibc","purl":"pkg:rpm/opensuse/glibc&distro=openSUSE%20Leap%2015.2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.26-lp152.26.6.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"glibc":"2.26-lp152.26.6.1","glibc-32bit":"2.26-lp152.26.6.1","glibc-devel":"2.26-lp152.26.6.1","glibc-devel-32bit":"2.26-lp152.26.6.1","glibc-devel-static":"2.26-lp152.26.6.1","glibc-devel-static-32bit":"2.26-lp152.26.6.1","glibc-extra":"2.26-lp152.26.6.1","glibc-html":"2.26-lp152.26.6.1","glibc-i18ndata":"2.26-lp152.26.6.1","glibc-info":"2.26-lp152.26.6.1","glibc-locale":"2.26-lp152.26.6.1","glibc-locale-base":"2.26-lp152.26.6.1","glibc-locale-base-32bit":"2.26-lp152.26.6.1","glibc-profile":"2.26-lp152.26.6.1","glibc-profile-32bit":"2.26-lp152.26.6.1","glibc-utils":"2.26-lp152.26.6.1","glibc-utils-32bit":"2.26-lp152.26.6.1","nscd":"2.26-lp152.26.6.1"}]},"package":{"ecosystem":"openSUSE:Leap 15.2","name":"glibc-testsuite-src","purl":"pkg:rpm/opensuse/glibc-testsuite-src&distro=openSUSE%20Leap%2015.2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.26-lp152.26.6.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for glibc fixes the following issues:\n\n- Fix buffer overrun in EUC-KR conversion module (CVE-2019-25013, bsc#1182117, BZ #24973)\n- x86: Harden printf against non-normal long double values (CVE-2020-29573, bsc#1179721, BZ #26649)\n- gconv: Fix assertion failure in ISO-2022-JP-3 module (CVE-2021-3326, bsc#1181505, BZ #27256)\n- iconv: Accept redundant shift sequences in IBM1364 (CVE-2020-27618, bsc#1178386, BZ #26224)\n- iconv: Fix incorrect UCS4 inner loop bounds (CVE-2020-29562, bsc#1179694, BZ #26923)\n- Fix parsing of /sys/devices/system/cpu/online (bsc#1180038, BZ #25859)\n\nThis update was imported from the SUSE:SLE-15:Update update project.","id":"openSUSE-SU-2021:0358-1","modified":"2021-02-27T21:33:28Z","published":"2021-02-27T21:33:28Z","references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WMNRZB427QFJOPYP4EA4KBZOTT622NY3/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1178386"},{"type":"REPORT","url":"https://bugzilla.suse.com/1179694"},{"type":"REPORT","url":"https://bugzilla.suse.com/1179721"},{"type":"REPORT","url":"https://bugzilla.suse.com/1180038"},{"type":"REPORT","url":"https://bugzilla.suse.com/1181505"},{"type":"REPORT","url":"https://bugzilla.suse.com/1182117"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-25013"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-27618"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-29562"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-29573"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-3326"}],"related":["CVE-2019-25013","CVE-2020-27618","CVE-2020-29562","CVE-2020-29573","CVE-2021-3326"],"summary":"Security update for glibc","upstream":["CVE-2019-25013","CVE-2020-27618","CVE-2020-29562","CVE-2020-29573","CVE-2021-3326"]}