A stack overflow vulnerability in the catopen function was found, causing applications which pass long strings to the catopen function to crash or, potentially execute arbitrary code.
Upstream bug:
https://sourceware.org/bugzilla/showbug.cgi?id=17905
CVE assignment:
http://seclists.org/oss-sec/2016/q1/153
An integer overflow vulnerability was found in hcreate and hcreater which can result in an out-of-bound memory access. This could lead to application crashes or, potentially, arbitrary code execution.
Upstream bug:
https://sourceware.org/bugzilla/showbug.cgi?id=18240
CVE assignment:
http://seclists.org/oss-sec/2016/q1/153
It was found that out-of-range time values passed to the strftime function may cause it to crash, leading to a denial of service, or potentially disclosure information.
Upstream bug:
https://sourceware.org/bugzilla/showbug.cgi?id=18985
CVE assignment:
http://seclists.org/oss-sec/2016/q1/153