You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa glibc

Sigurnosni nedostaci programskog paketa glibc

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LMV

—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDVSA-2014:175
http://www.mandriva.com/en/support/security/
_______________________________________________________________________

Package : glibc
Date : September 5, 2014
Affected: Business Server 1.0
_______________________________________________________________________

Problem Description:

Multiple vulnerabilities has been found and corrected in glibc:

When converting IBM930 code with iconv(), if IBM930 code which includes
invalid multibyte character 0xffff is specified, then iconv() segfaults
(CVE-2012-6656).

Off-by-one error in the __gconv_translit_find function in gconv_trans.c
in GNU C Library (aka glibc) allows context-dependent attackers to
cause a denial of service (crash) or execute arbitrary code via vectors
related to the CHARSET environment variable and gconv transliteration
modules (CVE-2014-5119).

Crashes were reported in the IBM code page decoding functions (IBM933,
IBM935, IBM937, IBM939, IBM1364) (CVE-2014-6040).

The updated packages have been patched to correct these issues.
_______________________________________________________________________

References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6656
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5119
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6040
https://rhn.redhat.com/errata/RHSA-2014-1110.html
https://sourceware.org/bugzilla/show_bug.cgi?id=14134
https://sourceware.org/bugzilla/show_bug.cgi?id=17325
http://seclists.org/oss-sec/2014/q3/485
https://bugzilla.redhat.com/show_bug.cgi?id=1135841
_______________________________________________________________________

Updated Packages:

Mandriva Business Server 1/X86_64:
85b7b4e252324a0590706605fe3a9d96 mbs1/x86_64/glibc-2.14.1-12.9.mbs1.x86_64.rpm
63cd91495f99e794eb0281b7c9ee2e32 mbs1/x86_64/glibc-devel-2.14.1-12.9.mbs1.x86_64.rpm
21d0709e256566ee526e9fbb0197b637 mbs1/x86_64/glibc-doc-2.14.1-12.9.mbs1.noarch.rpm
8ea25400b2d708f2d7da22df4a5a6228 mbs1/x86_64/glibc-doc-pdf-2.14.1-12.9.mbs1.noarch.rpm
dfc7aae076e0a66b236968ee0af8e7da mbs1/x86_64/glibc-i18ndata-2.14.1-12.9.mbs1.x86_64.rpm
ebf493606c89def3d6bfca87749bbf03 mbs1/x86_64/glibc-profile-2.14.1-12.9.mbs1.x86_64.rpm
6ad78068de0280f4584d5e8b70890de5 mbs1/x86_64/glibc-static-devel-2.14.1-12.9.mbs1.x86_64.rpm
c796168f27f0236d7cd9123aba6e5ee8 mbs1/x86_64/glibc-utils-2.14.1-12.9.mbs1.x86_64.rpm
044ada512f6397981550cb3342a48173 mbs1/x86_64/nscd-2.14.1-12.9.mbs1.x86_64.rpm
5fc48f30a7f358c201b72be63a7a677d mbs1/SRPMS/glibc-2.14.1-12.9.mbs1.src.rpm
_______________________________________________________________________

To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:

gpg –recv-keys –keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/en/support/security/advisories/

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com
_______________________________________________________________________

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
<security*mandriva.com>
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1.4.12 (GNU/Linux)

iD8DBQFUCX8NmqjQ0CJFipgRAqzxAJ9pVZoPY825wB33ukpXc3ofeE0xugCg0Gv0
gUv75jIjJhnMP0ZKVat47Bg=
=ijrN
—–END PGP SIGNATURE—–

To unsubscribe, send a email to sympa@mandrivalinux.org
with this subject : unsubscribe security-announce
_______________________________________________________
Want to buy your Pack or Services from Mandriva?
Go to http://store.mandriva.com
_______________________________________________________

AutorMarko Stanec
Cert idNCERT-REF-2014-09-0017-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
Izvorhttp://www.adobe.com/
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa apache

Otkriveni su sigurnosni nedostaci u programskom paketu apache, odnosno komponentama tomcat i php za operacijski sustav HP-UX B.11.31. Otkriveni nedostaci...

Close