SCIENTIFIC-LINUX-ERRATA Archives

January 2015

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Wed, 7 Jan 2015 23:20:20 +0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (66 lines)
Synopsis:          Moderate: glibc security and bug fix update
Advisory ID:       SLSA-2015:0016-1
Issue Date:        2015-01-07
CVE Numbers:       CVE-2014-7817
                   CVE-2014-6040
--

An out-of-bounds read flaw was found in the way glibc's iconv() function
converted certain encoded data to UTF-8. An attacker able to make an
application call the iconv() function with a specially crafted argument
could use this flaw to crash that application. (CVE-2014-6040)

It was found that the wordexp() function would perform command
substitution even when the WRDE_NOCMD flag was specified. An attacker able
to provide specially crafted input to an application using the wordexp()
function, and not sanitizing the input correctly, could potentially use
this flaw to execute arbitrary commands with the credentials of the user
running that application. (CVE-2014-7817)

This update also fixes the following bugs:

* Previously, when an address lookup using the getaddrinfo() function for
the AF_UNSPEC value was performed on a defective DNS server, the server in
some cases responded with a valid response for the A record, but a
referral response for the AAAA record, which resulted in a lookup failure.
A prior update was implemented for getaddrinfo() to return the valid
response, but it contained a typographical error, due to which the lookup
could under some circumstances still fail. This error has been corrected
and getaddrinfo() now returns a valid response in the described
circumstances.

* An error in the dlopen() library function previously caused recursive
calls to dlopen() to terminate unexpectedly or to abort with a library
assertion. This error has been fixed and recursive calls to dlopen() no
longer crash or abort.
--

SL6
  x86_64
    glibc-2.12-1.149.el6_6.4.i686.rpm
    glibc-2.12-1.149.el6_6.4.x86_64.rpm
    glibc-common-2.12-1.149.el6_6.4.x86_64.rpm
    glibc-debuginfo-2.12-1.149.el6_6.4.i686.rpm
    glibc-debuginfo-2.12-1.149.el6_6.4.x86_64.rpm
    glibc-debuginfo-common-2.12-1.149.el6_6.4.i686.rpm
    glibc-debuginfo-common-2.12-1.149.el6_6.4.x86_64.rpm
    glibc-devel-2.12-1.149.el6_6.4.i686.rpm
    glibc-devel-2.12-1.149.el6_6.4.x86_64.rpm
    glibc-headers-2.12-1.149.el6_6.4.x86_64.rpm
    glibc-utils-2.12-1.149.el6_6.4.x86_64.rpm
    nscd-2.12-1.149.el6_6.4.x86_64.rpm
    glibc-static-2.12-1.149.el6_6.4.i686.rpm
    glibc-static-2.12-1.149.el6_6.4.x86_64.rpm
  i386
    glibc-2.12-1.149.el6_6.4.i686.rpm
    glibc-common-2.12-1.149.el6_6.4.i686.rpm
    glibc-debuginfo-2.12-1.149.el6_6.4.i686.rpm
    glibc-debuginfo-common-2.12-1.149.el6_6.4.i686.rpm
    glibc-devel-2.12-1.149.el6_6.4.i686.rpm
    glibc-headers-2.12-1.149.el6_6.4.i686.rpm
    glibc-utils-2.12-1.149.el6_6.4.i686.rpm
    nscd-2.12-1.149.el6_6.4.i686.rpm
    glibc-static-2.12-1.149.el6_6.4.i686.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2