CVE-2016-10739
published 2019-01-21CVE-2016-10739: In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by…
PriorityP425medium5.3CVSS 3.0
AVLACLPRLUINSUCLILAL
EPSS
0.48%
38.6th percentile
In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters, which could lead applications to incorrectly assume that it had parsed a valid string, without the possibility of embedded HTTP headers or other potentially dangerous substrings.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.28-6 (bookworm) | glibc 2.28-6 (bookworm) |
| debian | python2.7 | < python2.7 2.7.18~rc1-1 (bullseye) | python2.7 2.7.18~rc1-1 (bullseye) |
| gnu | glibc | <= 2.28 | — |
| gnu | glibc | >= 0 < 2.28-6 | 2.28-6 |
| gnu | glibc | >= 0 < 2.28-6 | 2.28-6 |
| gnu | glibc | >= 0 < 2.28-6 | 2.28-6 |
| gnu | glibc | >= 0 < 2.28-6 | 2.28-6 |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_glibc_2.28-12_on_cbl_mariner_1.0 | — | — |
| msrc | cm1_python3_3.7.10-3_on_cbl_mariner_1.0 | — | — |
| opensuse | leap | — | — |
| python | python | 2.0 – 2.7.17 | — |
| python | python | >= 3.0 < 3.5.10 | 3.5.10 |
| python | python | >= 3.6.0 < 3.6.11 | 3.6.11 |
| python | python | >= 3.7.0 < 3.7.8 | 3.7.8 |
| python | python | >= 3.8.0 < 3.8.3 | 3.8.3 |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv5.3MEDIUM
vendor_msrc6.1MEDIUM
vendor_debian5.3LOW
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v3f8-6665-x7rx: An issue was discovered in urllib2 in Python 2
ghsa_unreviewed·2022-05-24·CVSS 5.3
CVE-2019-18348 [MEDIUM] CWE-74 GHSA-v3f8-6665-x7rx: An issue was discovered in urllib2 in Python 2
An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \r\n (specifically in the host component of a URL) followed by an HTTP header. This is similar to the CVE-2019-9740 query string issue and the CVE-2019-9947 path string issue. (This is not exploitable when glibc has CVE-2016-10739 fixed.)
GHSA
GHSA-8r2c-r3r4-4hcp: In the GNU C Library (aka glibc or libc6) through 2
ghsa_unreviewed·2022-05-14
CVE-2016-10739 [MEDIUM] CWE-20 GHSA-8r2c-r3r4-4hcp: In the GNU C Library (aka glibc or libc6) through 2
In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters, which could lead applications to incorrectly assume that it had parsed a valid string, without the possibility of embedded HTTP headers or other potentially dangerous substrings.
OSV
CVE-2019-18348: An issue was discovered in urllib2 in Python 2
osv·2019-10-23·CVSS 5.3
CVE-2019-18348 [MEDIUM] CVE-2019-18348: An issue was discovered in urllib2 in Python 2
An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \r\n (specifically in the host component of a URL) followed by an HTTP header. This is similar to the CVE-2019-9740 query string issue and the CVE-2019-9947 path string issue. (This is not exploitable when glibc has CVE-2016-10739 fixed.). This is fixed in: v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1; v3.6.11, v3.6.11rc1, v3.6.12; v3.7.8, v3.7.8rc1, v3.7.9; v3.8.3, v3.8.3rc1, v3.8.4, v3.8.4rc1, v3.8.5, v3.8.6, v3.8.6rc1.
OSV
CVE-2016-10739: In the GNU C Library (aka glibc or libc6) through 2
osv·2019-01-21·CVSS 5.3
CVE-2016-10739 [MEDIUM] CVE-2016-10739: In the GNU C Library (aka glibc or libc6) through 2
In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters, which could lead applications to incorrectly assume that it had parsed a valid string, without the possibility of embedded HTTP headers or other potentially dangerous substrings.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Microsoft
An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection is possible if the attacker controls a url parameter as demonstrated by the first
vendor_msrc·2019-10-08·CVSS 6.1
CVE-2019-18348 [MEDIUM] CWE-74 An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection is possible if the attacker controls a url parameter as demonstrated by the first
An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection is possible if the attacker controls a url parameter as demonstrated by the first argument to urllib.request.urlopen with \r\n (specifically in the host component of a URL) followed by an HTTP header. This is similar to the CVE-2019-9740 query string issue and the CVE-2019-9947 path string issue. (This is not exploitable when glibc has CVE-2016-10739 fixed.). This is fixed in: v2.7.18 v2.7.18rc1; v3.5.10 v3.5.10rc1; v3.6.11 v3.6.11rc1 v3.6.12; v3.7.8 v3.7.8rc1 v3.7.9; v3.8.3 v3.8.3rc1 v3.8.4 v3.8.4rc1 v3.8.5 v3.8.6 v3.8.6rc1.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
O
Red Hat
python: CRLF injection via the host part of the url passed to urlopen()
vendor_redhat·2019-07-04·CVSS 5.3
CVE-2019-18348 [MEDIUM] CWE-113 python: CRLF injection via the host part of the url passed to urlopen()
python: CRLF injection via the host part of the url passed to urlopen()
An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \r\n (specifically in the host component of a URL) followed by an HTTP header. This is similar to the CVE-2019-9740 query string issue and the CVE-2019-9947 path string issue. (This is not exploitable when glibc has CVE-2016-10739 fixed.). This is fixed in: v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1; v3.6.11, v3.6.11rc1, v3.6.12; v3.7.8, v3.7.8rc1, v3.7.9; v3.8.3, v3.8.3rc1, v3.8.4, v3.8.4rc1, v3.8.5, v3.8.6, v3.8.6rc1.
A CRLF injection flaw was discovered in python in the way URLs
Microsoft
In the GNU C Library (aka glibc or libc6) through 2.28 the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters which c
vendor_msrc·2019-01-08·CVSS 5.3
CVE-2016-10739 [MEDIUM] CWE-20 In the GNU C Library (aka glibc or libc6) through 2.28 the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters which c
In the GNU C Library (aka glibc or libc6) through 2.28 the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters which could lead applications to incorrectly assume that it had parsed a valid string without the possibility of embedded HTTP headers or other potentially dangerous substrings.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this w
Debian
CVE-2019-18348: python2.7 - An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Py...
vendor_debian·2019·CVSS 5.3
CVE-2019-18348 [MEDIUM] CVE-2019-18348: python2.7 - An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Py...
An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \r\n (specifically in the host component of a URL) followed by an HTTP header. This is similar to the CVE-2019-9740 query string issue and the CVE-2019-9947 path string issue. (This is not exploitable when glibc has CVE-2016-10739 fixed.). This is fixed in: v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1; v3.6.11, v3.6.11rc1, v3.6.12; v3.7.8, v3.7.8rc1, v3.7.9; v3.8.3, v3.8.3rc1, v3.8.4, v3.8.4rc1, v3.8.5, v3.8.6, v3.8.6rc1.
Scope: local
bullseye: resolved (fixed in 2.7.18~rc1-1)
Red Hat
glibc: getaddrinfo should reject IP addresses with trailing characters
vendor_redhat·2016-04-28·CVSS 5.3
CVE-2016-10739 [MEDIUM] CWE-20 glibc: getaddrinfo should reject IP addresses with trailing characters
glibc: getaddrinfo should reject IP addresses with trailing characters
In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters, which could lead applications to incorrectly assume that it had parsed a valid string, without the possibility of embedded HTTP headers or other potentially dangerous substrings.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: glibc (Red Hat Enterprise Linux 5) - Out of sup
Debian
CVE-2016-10739: glibc - In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function...
vendor_debian·2016·CVSS 5.3
CVE-2016-10739 [MEDIUM] CVE-2016-10739: glibc - In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function...
In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters, which could lead applications to incorrectly assume that it had parsed a valid string, without the possibility of embedded HTTP headers or other potentially dangerous substrings.
Scope: local
bookworm: resolved (fixed in 2.28-6)
bullseye: resolved (fixed in 2.28-6)
forky: resolved (fixed in 2.28-6)
sid: resolved (fixed in 2.28-6)
trixie: resolved (fixed in 2.28-6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-18348 python35: python: CRLF injection via the host part of the url passed to urlopen() [fedora-all]
bugzilla·2019-10-24·CVSS 6.1
CVE-2019-18348 [MEDIUM] CVE-2019-18348 python35: python: CRLF injection via the host part of the url passed to urlopen() [fedora-all]
CVE-2019-18348 python35: python: CRLF injection via the host part of the url passed to urlopen() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue aff
Bugzilla
CVE-2019-18348 python34: python: CRLF injection via the host part of the url passed to urlopen() [fedora-all]
bugzilla·2019-10-24·CVSS 6.1
CVE-2019-18348 [MEDIUM] CVE-2019-18348 python34: python: CRLF injection via the host part of the url passed to urlopen() [fedora-all]
CVE-2019-18348 python34: python: CRLF injection via the host part of the url passed to urlopen() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue aff
Bugzilla
CVE-2019-18348 python38: python: CRLF injection via the host part of the url passed to urlopen() [fedora-all]
bugzilla·2019-10-24·CVSS 6.1
CVE-2019-18348 [MEDIUM] CVE-2019-18348 python38: python: CRLF injection via the host part of the url passed to urlopen() [fedora-all]
CVE-2019-18348 python38: python: CRLF injection via the host part of the url passed to urlopen() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue aff
Bugzilla
CVE-2019-18348 python36: python: CRLF injection via the host part of the url passed to urlopen() [fedora-all]
bugzilla·2019-10-24·CVSS 6.1
CVE-2019-18348 [MEDIUM] CVE-2019-18348 python36: python: CRLF injection via the host part of the url passed to urlopen() [fedora-all]
CVE-2019-18348 python36: python: CRLF injection via the host part of the url passed to urlopen() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue aff
Bugzilla
CVE-2019-18348 python34: python: CRLF injection via the host part of the url passed to urlopen() [epel-all]
bugzilla·2019-10-24·CVSS 6.1
CVE-2019-18348 [MEDIUM] CVE-2019-18348 python34: python: CRLF injection via the host part of the url passed to urlopen() [epel-all]
CVE-2019-18348 python34: python: CRLF injection via the host part of the url passed to urlopen() [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2019-18348 python2: python: CRLF injection via the host part of the url passed to urlopen() [fedora-all]
bugzilla·2019-10-24·CVSS 6.1
CVE-2019-18348 [MEDIUM] CVE-2019-18348 python2: python: CRLF injection via the host part of the url passed to urlopen() [fedora-all]
CVE-2019-18348 python2: python: CRLF injection via the host part of the url passed to urlopen() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affe
Bugzilla
CVE-2019-18348 python26: python: CRLF injection via the host part of the url passed to urlopen() [fedora-all]
bugzilla·2019-10-24·CVSS 6.1
CVE-2019-18348 [MEDIUM] CVE-2019-18348 python26: python: CRLF injection via the host part of the url passed to urlopen() [fedora-all]
CVE-2019-18348 python26: python: CRLF injection via the host part of the url passed to urlopen() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue aff
Bugzilla
CVE-2019-18348 python3: python: CRLF injection via the host part of the url passed to urlopen() [fedora-all]
bugzilla·2019-10-24·CVSS 6.1
CVE-2019-18348 [MEDIUM] CVE-2019-18348 python3: python: CRLF injection via the host part of the url passed to urlopen() [fedora-all]
CVE-2019-18348 python3: python: CRLF injection via the host part of the url passed to urlopen() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affe
Bugzilla
CVE-2019-18348 python: CRLF injection via the host part of the url passed to urlopen()
bugzilla·2019-07-05·CVSS 5.3
CVE-2019-18348 [MEDIUM] CVE-2019-18348 python: CRLF injection via the host part of the url passed to urlopen()
CVE-2019-18348 python: CRLF injection via the host part of the url passed to urlopen()
An issue was discovered in urllib/urllib2 in Python. CRLF injection is possible if the attacker controls the host part of the url parameter passed to urlopen().
The fix for CVE-2019-9947 is ineffective if the glibc version used by python is still affected by CVE-2016-10739. The original fix for CVE-2019-9947 only checked the part of the URL after the port (e.g. in "http://server:7777/my/path?query" only "/my/path?query" was checked for invalid characters) so if an attacker can control the hostname part he is still able to inject HTTP headers. Due to CVE-2016-10739, getaddrinfo() resolves an invalid hostname as a valid one, so the URL can contain CLRF sequences and, at the same time, it can be resolved
Bugzilla
CVE-2019-9947 python: CRLF injection via the path part of the url passed to urlopen()
bugzilla·2019-04-03·CVSS 6.1
CVE-2019-9947 [MEDIUM] CVE-2019-9947 python: CRLF injection via the path part of the url passed to urlopen()
CVE-2019-9947 python: CRLF injection via the path part of the url passed to urlopen()
An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in
Python 3.x through 3.7.2. CRLF injection is possible if the attacker controls a
url parameter, as demonstrated by the first argument to urllib.request.urlopen
with \r\n (specifically in the path component of a URL) followed by an HTTP
header or a Redis command. This is similar to CVE-2019-9740 query string issue.
Reference:
https://bugs.python.org/issue35906
Discussion:
Created python-urllib3 tracking bugs for this issue:
Affects: fedora-all [bug 1695599]
---
Created python3-urllib3 tracking bugs for this issue:
Affects: epel-all [bug 1695600]
---
The main Python issue became https://bugs.python.org/issue30458 which is
Bugzilla
CVE-2016-10739 glibc: getaddrinfo should reject IP addresses with trailing characters
bugzilla·2016-06-17·CVSS 5.3
CVE-2016-10739 [MEDIUM] CVE-2016-10739 glibc: getaddrinfo should reject IP addresses with trailing characters
CVE-2016-10739 glibc: getaddrinfo should reject IP addresses with trailing characters
For historic reasons, inet_addr and inet_aton accept trailing garbage. Some parsers rely on this (for example, libresolv when it parses “nameserver” directives in /etc/resolv.conf).
This causes problems because some applications assume that a successful parse as an IPv4 address means that the string consists of just an IPv4 address, and nothing more.
Glibc should add a check for trailing garbage and relegate the old behavior to a compatibility symbol.
For backporting, glibc should just fix getaddrinfo (and related functions if necessary) so that they will not accept trailing garbage.
Upstream bug :
https://sourceware.org/bugzilla/show_bug.cgi?id=20018
Additional note :
When used in combination with
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00082.htmlhttp://www.securityfocus.com/bid/106672https://access.redhat.com/errata/RHSA-2019:2118https://access.redhat.com/errata/RHSA-2019:3513https://bugzilla.redhat.com/show_bug.cgi?id=1347549https://sourceware.org/bugzilla/show_bug.cgi?id=20018http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00082.htmlhttp://www.securityfocus.com/bid/106672https://access.redhat.com/errata/RHSA-2019:2118https://access.redhat.com/errata/RHSA-2019:3513https://bugzilla.redhat.com/show_bug.cgi?id=1347549https://sourceware.org/bugzilla/show_bug.cgi?id=20018
2019-01-21
Published