<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for glibc</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2015:0439-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2014-08-29T01:15:58Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2014-08-29T01:15:58Z</InitialReleaseDate>
    <CurrentReleaseDate>2014-08-29T01:15:58Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for glibc</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">
This glibc update fixes a critical privilege escalation problem and two 
non-security issues:

    * bnc#892073: An off-by-one error leading to a heap-based buffer
      overflow was found in __gconv_translit_find(). An exploit that
      targets the problem is publicly available. (CVE-2014-5119)
    * bnc#892065: setenv-alloca.patch: Avoid unbound alloca in setenv.
    * bnc#888347: printf-multibyte-format.patch: Don't parse %s format
      argument as multi-byte string.

Security Issues:

    * CVE-2014-5119
      &lt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5119&gt;

</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">sdksp3-glibc,sledsp3-glibc,slessp3-glibc</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150439-1/</URL>
      <Description>Link for SUSE-SU-2015:0439-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2015-March/001271.html</URL>
      <Description>E-Mail link for SUSE-SU-2015:0439-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/691365</URL>
      <Description>SUSE Bug 691365</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/779320</URL>
      <Description>SUSE Bug 779320</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/791928</URL>
      <Description>SUSE Bug 791928</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/801246</URL>
      <Description>SUSE Bug 801246</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/811979</URL>
      <Description>SUSE Bug 811979</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/813121</URL>
      <Description>SUSE Bug 813121</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/819347</URL>
      <Description>SUSE Bug 819347</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/822210</URL>
      <Description>SUSE Bug 822210</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/827811</URL>
      <Description>SUSE Bug 827811</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/828235</URL>
      <Description>SUSE Bug 828235</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/828637</URL>
      <Description>SUSE Bug 828637</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/830268</URL>
      <Description>SUSE Bug 830268</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/834594</URL>
      <Description>SUSE Bug 834594</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/836746</URL>
      <Description>SUSE Bug 836746</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/839870</URL>
      <Description>SUSE Bug 839870</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/844309</URL>
      <Description>SUSE Bug 844309</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/847227</URL>
      <Description>SUSE Bug 847227</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/854445</URL>
      <Description>SUSE Bug 854445</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/863499</URL>
      <Description>SUSE Bug 863499</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/864081</URL>
      <Description>SUSE Bug 864081</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/872832</URL>
      <Description>SUSE Bug 872832</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/882028</URL>
      <Description>SUSE Bug 882028</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/882600</URL>
      <Description>SUSE Bug 882600</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/883217</URL>
      <Description>SUSE Bug 883217</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/886416</URL>
      <Description>SUSE Bug 886416</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/887022</URL>
      <Description>SUSE Bug 887022</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/888347</URL>
      <Description>SUSE Bug 888347</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/891843</URL>
      <Description>SUSE Bug 891843</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/892065</URL>
      <Description>SUSE Bug 892065</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/892073</URL>
      <Description>SUSE Bug 892073</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/894553</URL>
      <Description>SUSE Bug 894553</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/894556</URL>
      <Description>SUSE Bug 894556</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/903288</URL>
      <Description>SUSE Bug 903288</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/904461</URL>
      <Description>SUSE Bug 904461</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/906371</URL>
      <Description>SUSE Bug 906371</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/909053</URL>
      <Description>SUSE Bug 909053</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/913646</URL>
      <Description>SUSE Bug 913646</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/915526</URL>
      <Description>SUSE Bug 915526</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/916222</URL>
      <Description>SUSE Bug 916222</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/917072</URL>
      <Description>SUSE Bug 917072</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/919678</URL>
      <Description>SUSE Bug 919678</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2012-4412/</URL>
      <Description>SUSE CVE CVE-2012-4412 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2012-6656/</URL>
      <Description>SUSE CVE CVE-2012-6656 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2013-0242/</URL>
      <Description>SUSE CVE CVE-2013-0242 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2013-1914/</URL>
      <Description>SUSE CVE CVE-2013-1914 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2013-4237/</URL>
      <Description>SUSE CVE CVE-2013-4237 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2013-4332/</URL>
      <Description>SUSE CVE CVE-2013-4332 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2013-4357/</URL>
      <Description>SUSE CVE CVE-2013-4357 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2013-4458/</URL>
      <Description>SUSE CVE CVE-2013-4458 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2013-4788/</URL>
      <Description>SUSE CVE CVE-2013-4788 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2013-7423/</URL>
      <Description>SUSE CVE CVE-2013-7423 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-0475/</URL>
      <Description>SUSE CVE CVE-2014-0475 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-4043/</URL>
      <Description>SUSE CVE CVE-2014-4043 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-5119/</URL>
      <Description>SUSE CVE CVE-2014-5119 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-6040/</URL>
      <Description>SUSE CVE CVE-2014-6040 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-7817/</URL>
      <Description>SUSE CVE CVE-2014-7817 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-9402/</URL>
      <Description>SUSE CVE CVE-2014-9402 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-0235/</URL>
      <Description>SUSE CVE CVE-2015-0235 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-1472/</URL>
      <Description>SUSE CVE CVE-2015-1472 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Desktop 11 SP3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Desktop 11 SP3">
        <FullProductName ProductID="SUSE Linux Enterprise Desktop 11 SP3" CPE="cpe:/o:suse:suse_sled:11:sp3">SUSE Linux Enterprise Desktop 11 SP3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 11 SP3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 11 SP3">
        <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3" CPE="cpe:/o:suse:suse_sles:11:sp3">SUSE Linux Enterprise Server 11 SP3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 11 SP3-TERADATA">
        <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA" CPE="cpe:/o:suse:sles:11:sp3:teradata">SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 11 SP3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server for SAP Applications 11 SP3">
        <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 11 SP3" CPE="cpe:/o:suse:sles_sap:11:sp3">SUSE Linux Enterprise Server for SAP Applications 11 SP3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Software Development Kit 11 SP3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Software Development Kit 11 SP3">
        <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 11 SP3" CPE="cpe:/a:suse:sle-sdk:11:sp3">SUSE Linux Enterprise Software Development Kit 11 SP3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="glibc-html-2.11.3-17.72.14">
      <FullProductName ProductID="glibc-html-2.11.3-17.72.14">glibc-html-2.11.3-17.72.14</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="glibc-info-2.11.3-17.72.14">
      <FullProductName ProductID="glibc-info-2.11.3-17.72.14">glibc-info-2.11.3-17.72.14</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="glibc-2.11.3-17.72.14">
      <FullProductName ProductID="glibc-2.11.3-17.72.14">glibc-2.11.3-17.72.14</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="glibc-32bit-2.11.3-17.72.14">
      <FullProductName ProductID="glibc-32bit-2.11.3-17.72.14">glibc-32bit-2.11.3-17.72.14</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="glibc-devel-2.11.3-17.72.14">
      <FullProductName ProductID="glibc-devel-2.11.3-17.72.14">glibc-devel-2.11.3-17.72.14</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="glibc-devel-32bit-2.11.3-17.72.14">
      <FullProductName ProductID="glibc-devel-32bit-2.11.3-17.72.14">glibc-devel-32bit-2.11.3-17.72.14</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="glibc-i18ndata-2.11.3-17.72.14">
      <FullProductName ProductID="glibc-i18ndata-2.11.3-17.72.14">glibc-i18ndata-2.11.3-17.72.14</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="glibc-locale-2.11.3-17.72.14">
      <FullProductName ProductID="glibc-locale-2.11.3-17.72.14">glibc-locale-2.11.3-17.72.14</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="glibc-locale-32bit-2.11.3-17.72.14">
      <FullProductName ProductID="glibc-locale-32bit-2.11.3-17.72.14">glibc-locale-32bit-2.11.3-17.72.14</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="nscd-2.11.3-17.72.14">
      <FullProductName ProductID="nscd-2.11.3-17.72.14">nscd-2.11.3-17.72.14</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="glibc-locale-x86-2.11.3-17.72.14">
      <FullProductName ProductID="glibc-locale-x86-2.11.3-17.72.14">glibc-locale-x86-2.11.3-17.72.14</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="glibc-profile-2.11.3-17.72.14">
      <FullProductName ProductID="glibc-profile-2.11.3-17.72.14">glibc-profile-2.11.3-17.72.14</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="glibc-profile-32bit-2.11.3-17.72.14">
      <FullProductName ProductID="glibc-profile-32bit-2.11.3-17.72.14">glibc-profile-32bit-2.11.3-17.72.14</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="glibc-profile-x86-2.11.3-17.72.14">
      <FullProductName ProductID="glibc-profile-x86-2.11.3-17.72.14">glibc-profile-x86-2.11.3-17.72.14</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="glibc-x86-2.11.3-17.72.14">
      <FullProductName ProductID="glibc-x86-2.11.3-17.72.14">glibc-x86-2.11.3-17.72.14</FullProductName>
    </Branch>
    <Relationship ProductReference="glibc-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 11 SP3:glibc-2.11.3-17.72.14">glibc-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Desktop 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-32bit-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 11 SP3:glibc-32bit-2.11.3-17.72.14">glibc-32bit-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Desktop 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-devel-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-2.11.3-17.72.14">glibc-devel-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Desktop 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-devel-32bit-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-32bit-2.11.3-17.72.14">glibc-devel-32bit-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Desktop 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-i18ndata-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 11 SP3:glibc-i18ndata-2.11.3-17.72.14">glibc-i18ndata-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Desktop 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-locale-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-2.11.3-17.72.14">glibc-locale-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Desktop 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-locale-32bit-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-32bit-2.11.3-17.72.14">glibc-locale-32bit-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Desktop 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="nscd-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 11 SP3:nscd-2.11.3-17.72.14">nscd-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Desktop 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3:glibc-2.11.3-17.72.14">glibc-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-32bit-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3:glibc-32bit-2.11.3-17.72.14">glibc-32bit-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-devel-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3:glibc-devel-2.11.3-17.72.14">glibc-devel-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-devel-32bit-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3:glibc-devel-32bit-2.11.3-17.72.14">glibc-devel-32bit-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-html-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3:glibc-html-2.11.3-17.72.14">glibc-html-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-i18ndata-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3:glibc-i18ndata-2.11.3-17.72.14">glibc-i18ndata-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-info-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3:glibc-info-2.11.3-17.72.14">glibc-info-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-locale-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3:glibc-locale-2.11.3-17.72.14">glibc-locale-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-locale-32bit-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3:glibc-locale-32bit-2.11.3-17.72.14">glibc-locale-32bit-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-locale-x86-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3:glibc-locale-x86-2.11.3-17.72.14">glibc-locale-x86-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-profile-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3:glibc-profile-2.11.3-17.72.14">glibc-profile-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-profile-32bit-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3:glibc-profile-32bit-2.11.3-17.72.14">glibc-profile-32bit-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-profile-x86-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3:glibc-profile-x86-2.11.3-17.72.14">glibc-profile-x86-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-x86-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3:glibc-x86-2.11.3-17.72.14">glibc-x86-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="nscd-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3:nscd-2.11.3-17.72.14">nscd-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-2.11.3-17.72.14">glibc-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-32bit-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-32bit-2.11.3-17.72.14">glibc-32bit-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-devel-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-2.11.3-17.72.14">glibc-devel-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-devel-32bit-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-32bit-2.11.3-17.72.14">glibc-devel-32bit-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-html-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-html-2.11.3-17.72.14">glibc-html-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-i18ndata-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-i18ndata-2.11.3-17.72.14">glibc-i18ndata-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-info-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-info-2.11.3-17.72.14">glibc-info-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-locale-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-2.11.3-17.72.14">glibc-locale-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-locale-32bit-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-32bit-2.11.3-17.72.14">glibc-locale-32bit-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-locale-x86-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-x86-2.11.3-17.72.14">glibc-locale-x86-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-profile-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-2.11.3-17.72.14">glibc-profile-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-profile-32bit-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-32bit-2.11.3-17.72.14">glibc-profile-32bit-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-profile-x86-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-x86-2.11.3-17.72.14">glibc-profile-x86-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-x86-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-x86-2.11.3-17.72.14">glibc-x86-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="nscd-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:nscd-2.11.3-17.72.14">nscd-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-2.11.3-17.72.14">glibc-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server for SAP Applications 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-32bit-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-32bit-2.11.3-17.72.14">glibc-32bit-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server for SAP Applications 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-devel-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-2.11.3-17.72.14">glibc-devel-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server for SAP Applications 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-devel-32bit-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-32bit-2.11.3-17.72.14">glibc-devel-32bit-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server for SAP Applications 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-html-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-html-2.11.3-17.72.14">glibc-html-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server for SAP Applications 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-i18ndata-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-i18ndata-2.11.3-17.72.14">glibc-i18ndata-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server for SAP Applications 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-info-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-info-2.11.3-17.72.14">glibc-info-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server for SAP Applications 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-locale-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-2.11.3-17.72.14">glibc-locale-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server for SAP Applications 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-locale-32bit-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-32bit-2.11.3-17.72.14">glibc-locale-32bit-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server for SAP Applications 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-locale-x86-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-x86-2.11.3-17.72.14">glibc-locale-x86-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server for SAP Applications 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-profile-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-2.11.3-17.72.14">glibc-profile-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server for SAP Applications 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-profile-32bit-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-32bit-2.11.3-17.72.14">glibc-profile-32bit-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server for SAP Applications 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-profile-x86-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-x86-2.11.3-17.72.14">glibc-profile-x86-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server for SAP Applications 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-x86-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-x86-2.11.3-17.72.14">glibc-x86-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server for SAP Applications 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="nscd-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 11 SP3:nscd-2.11.3-17.72.14">nscd-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Server for SAP Applications 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-html-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Software Development Kit 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-html-2.11.3-17.72.14">glibc-html-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Software Development Kit 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="glibc-info-2.11.3-17.72.14" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Software Development Kit 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-info-2.11.3-17.72.14">glibc-info-2.11.3-17.72.14 as a component of SUSE Linux Enterprise Software Development Kit 11 SP3</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer overflow in string/strcoll_l.c in the GNU C Library (aka glibc or libc6) 2.17 and earlier allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string, which triggers a heap-based buffer overflow.</Note>
    </Notes>
    <CVE>CVE-2012-4412</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150439-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2012-4412.html</URL>
        <Description>CVE-2012-4412</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/779320</URL>
        <Description>SUSE Bug 779320</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/848783</URL>
        <Description>SUSE Bug 848783</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/882910</URL>
        <Description>SUSE Bug 882910</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/920169</URL>
        <Description>SUSE Bug 920169</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/920338</URL>
        <Description>SUSE Bug 920338</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">iconvdata/ibm930.c in GNU C Library (aka glibc) before 2.16 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a multibyte character value of "0xffff" to the iconv function when converting IBM930 encoded data to UTF-8.</Note>
    </Notes>
    <CVE>CVE-2012-6656</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150439-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2012-6656.html</URL>
        <Description>CVE-2012-6656</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/894556</URL>
        <Description>SUSE Bug 894556</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/903057</URL>
        <Description>SUSE Bug 903057</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Buffer overflow in the extend_buffers function in the regular expression matcher (posix/regexec.c) in glibc, possibly 2.17 and earlier, allows context-dependent attackers to cause a denial of service (memory corruption and crash) via crafted multibyte characters.</Note>
    </Notes>
    <CVE>CVE-2013-0242</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150439-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2013-0242.html</URL>
        <Description>CVE-2013-0242</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/801246</URL>
        <Description>SUSE Bug 801246</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/848783</URL>
        <Description>SUSE Bug 848783</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/882910</URL>
        <Description>SUSE Bug 882910</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in GNU C Library (aka glibc or libc6) 2.17 and earlier allows remote attackers to cause a denial of service (crash) via a (1) hostname or (2) IP address that triggers a large number of domain conversion results.</Note>
    </Notes>
    <CVE>CVE-2013-1914</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150439-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2013-1914.html</URL>
        <Description>CVE-2013-1914</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/813121</URL>
        <Description>SUSE Bug 813121</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/826666</URL>
        <Description>SUSE Bug 826666</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/882910</URL>
        <Description>SUSE Bug 882910</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/941444</URL>
        <Description>SUSE Bug 941444</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">sysdeps/posix/readdir_r.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allows context-dependent attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a crafted (1) NTFS or (2) CIFS image.</Note>
    </Notes>
    <CVE>CVE-2013-4237</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150439-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2013-4237.html</URL>
        <Description>CVE-2013-4237</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/834594</URL>
        <Description>SUSE Bug 834594</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/882910</URL>
        <Description>SUSE Bug 882910</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/883022</URL>
        <Description>SUSE Bug 883022</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple integer overflows in malloc/malloc.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allow context-dependent attackers to cause a denial of service (heap corruption) via a large value to the (1) pvalloc, (2) valloc, (3) posix_memalign, (4) memalign, or (5) aligned_alloc functions.</Note>
    </Notes>
    <CVE>CVE-2013-4332</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150439-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2013-4332.html</URL>
        <Description>CVE-2013-4332</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1123874</URL>
        <Description>SUSE Bug 1123874</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/839870</URL>
        <Description>SUSE Bug 839870</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/882910</URL>
        <Description>SUSE Bug 882910</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service.</Note>
    </Notes>
    <CVE>CVE-2013-4357</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150439-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2013-4357.html</URL>
        <Description>CVE-2013-4357</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/844309</URL>
        <Description>SUSE Bug 844309</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/883217</URL>
        <Description>SUSE Bug 883217</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/903057</URL>
        <Description>SUSE Bug 903057</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in GNU C Library (aka glibc or libc6) 2.18 and earlier allows remote attackers to cause a denial of service (crash) via a (1) hostname or (2) IP address that triggers a large number of AF_INET6 address results. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-1914.</Note>
    </Notes>
    <CVE>CVE-2013-4458</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150439-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2013-4458.html</URL>
        <Description>CVE-2013-4458</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1123874</URL>
        <Description>SUSE Bug 1123874</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/847227</URL>
        <Description>SUSE Bug 847227</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/883217</URL>
        <Description>SUSE Bug 883217</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/941444</URL>
        <Description>SUSE Bug 941444</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/955181</URL>
        <Description>SUSE Bug 955181</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/967023</URL>
        <Description>SUSE Bug 967023</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/980483</URL>
        <Description>SUSE Bug 980483</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The PTR_MANGLE implementation in the GNU C Library (aka glibc or libc6) 2.4, 2.17, and earlier, and Embedded GLIBC (EGLIBC) does not initialize the random value for the pointer guard, which makes it easier for context-dependent attackers to control execution flow by leveraging a buffer-overflow vulnerability in an application and using the known zero value pointer guard to calculate a pointer address.</Note>
    </Notes>
    <CVE>CVE-2013-4788</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150439-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2013-4788.html</URL>
        <Description>CVE-2013-4788</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1123874</URL>
        <Description>SUSE Bug 1123874</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/830268</URL>
        <Description>SUSE Bug 830268</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/882910</URL>
        <Description>SUSE Bug 882910</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/950944</URL>
        <Description>SUSE Bug 950944</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The send_dg function in resolv/res_send.c in GNU C Library (aka glibc or libc6) before 2.20 does not properly reuse file descriptors, which allows remote attackers to send DNS queries to unintended locations via a large number of requests that trigger a call to the getaddrinfo function.</Note>
    </Notes>
    <CVE>CVE-2013-7423</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>2.6</BaseScore>
        <Vector>AV:L/AC:H/Au:N/C:P/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150439-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2013-7423.html</URL>
        <Description>CVE-2013-7423</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1123874</URL>
        <Description>SUSE Bug 1123874</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915526</URL>
        <Description>SUSE Bug 915526</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="11">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2.20 allow context-dependent attackers to bypass ForceCommand restrictions and possibly have other unspecified impact via a .. (dot dot) in a (1) LC_*, (2) LANG, or other locale environment variable.</Note>
    </Notes>
    <CVE>CVE-2014-0475</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150439-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-0475.html</URL>
        <Description>CVE-2014-0475</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/887022</URL>
        <Description>SUSE Bug 887022</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/896776</URL>
        <Description>SUSE Bug 896776</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/916222</URL>
        <Description>SUSE Bug 916222</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="12">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The posix_spawn_file_actions_addopen function in glibc before 2.20 does not copy its path argument in accordance with the POSIX specification, which allows context-dependent attackers to trigger use-after-free vulnerabilities.</Note>
    </Notes>
    <CVE>CVE-2014-4043</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150439-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-4043.html</URL>
        <Description>CVE-2014-4043</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/882600</URL>
        <Description>SUSE Bug 882600</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/939797</URL>
        <Description>SUSE Bug 939797</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="13">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via vectors related to the CHARSET environment variable and gconv transliteration modules.</Note>
    </Notes>
    <CVE>CVE-2014-5119</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150439-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-5119.html</URL>
        <Description>CVE-2014-5119</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/892073</URL>
        <Description>SUSE Bug 892073</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/903057</URL>
        <Description>SUSE Bug 903057</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/916222</URL>
        <Description>SUSE Bug 916222</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="14">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">GNU C Library (aka glibc) before 2.20 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via a multibyte character value of "0xffff" to the iconv function when converting (1) IBM933, (2) IBM935, (3) IBM937, (4) IBM939, or (5) IBM1364 encoded data to UTF-8.</Note>
    </Notes>
    <CVE>CVE-2014-6040</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150439-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-6040.html</URL>
        <Description>CVE-2014-6040</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/894553</URL>
        <Description>SUSE Bug 894553</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/903057</URL>
        <Description>SUSE Bug 903057</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/916222</URL>
        <Description>SUSE Bug 916222</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="15">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containing "$((`...`))".</Note>
    </Notes>
    <CVE>CVE-2014-7817</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150439-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-7817.html</URL>
        <Description>CVE-2014-7817</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/906371</URL>
        <Description>SUSE Bug 906371</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="16">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2.21, when the DNS backend in the Name Service Switch configuration is enabled, allows remote attackers to cause a denial of service (infinite loop) by sending a positive answer while a network name is being process.</Note>
    </Notes>
    <CVE>CVE-2014-9402</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150439-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-9402.html</URL>
        <Description>CVE-2014-9402</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/910599</URL>
        <Description>SUSE Bug 910599</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="17">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."</Note>
    </Notes>
    <CVE>CVE-2015-0235</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150439-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-0235.html</URL>
        <Description>CVE-2015-0235</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/844309</URL>
        <Description>SUSE Bug 844309</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/913646</URL>
        <Description>SUSE Bug 913646</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/949238</URL>
        <Description>SUSE Bug 949238</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/954983</URL>
        <Description>SUSE Bug 954983</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="18">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during memory allocation, which allows context-dependent attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long line containing wide characters that are improperly handled in a wscanf call.</Note>
    </Notes>
    <CVE>CVE-2015-1472</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-devel-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-i18ndata-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-locale-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-32bit-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-profile-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:glibc-x86-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:nscd-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-html-2.11.3-17.72.14</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP3:glibc-info-2.11.3-17.72.14</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150439-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-1472.html</URL>
        <Description>CVE-2015-1472</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/916222</URL>
        <Description>SUSE Bug 916222</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/920341</URL>
        <Description>SUSE Bug 920341</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/922243</URL>
        <Description>SUSE Bug 922243</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
