SCIENTIFIC-LINUX-ERRATA Archives

April 2015

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Tue, 21 Apr 2015 14:06:47 +0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (60 lines)
Synopsis:          Moderate: glibc security and bug fix update
Advisory ID:       SLSA-2015:0863-1
Issue Date:        2015-04-21
CVE Numbers:       CVE-2013-7423
                   CVE-2015-1781
--

A buffer overflow flaw was found in the way glibc's gethostbyname_r() and
other related functions computed the size of a buffer when passed a
misaligned buffer as input. An attacker able to make an application call
any of these functions with a misaligned buffer could use this flaw to
crash the application or, potentially, execute arbitrary code with the
permissions of the user running the application. (CVE-2015-1781)

It was discovered that, under certain circumstances, glibc's getaddrinfo()
function would send DNS queries to random file descriptors. An attacker
could potentially use this flaw to send DNS queries to unintended
recipients, resulting in information disclosure or data loss due to the
application encountering corrupted data. (CVE-2013-7423)

This update also fixes the following bug:

* Previously, the nscd daemon did not properly reload modified data when
the user edited monitored nscd configuration files. As a consequence, nscd
returned stale data to system processes. This update adds a system of
inotify-based monitoring and stat-based backup monitoring for nscd
configuration files. As a result, nscd now detects changes to its
configuration files and reloads the data properly, which prevents it from
returning stale data.
--

SL6
  x86_64
    glibc-2.12-1.149.el6_6.7.i686.rpm
    glibc-2.12-1.149.el6_6.7.x86_64.rpm
    glibc-common-2.12-1.149.el6_6.7.x86_64.rpm
    glibc-debuginfo-2.12-1.149.el6_6.7.i686.rpm
    glibc-debuginfo-2.12-1.149.el6_6.7.x86_64.rpm
    glibc-debuginfo-common-2.12-1.149.el6_6.7.i686.rpm
    glibc-debuginfo-common-2.12-1.149.el6_6.7.x86_64.rpm
    glibc-devel-2.12-1.149.el6_6.7.i686.rpm
    glibc-devel-2.12-1.149.el6_6.7.x86_64.rpm
    glibc-headers-2.12-1.149.el6_6.7.x86_64.rpm
    glibc-utils-2.12-1.149.el6_6.7.x86_64.rpm
    nscd-2.12-1.149.el6_6.7.x86_64.rpm
    glibc-static-2.12-1.149.el6_6.7.i686.rpm
    glibc-static-2.12-1.149.el6_6.7.x86_64.rpm
  i386
    glibc-2.12-1.149.el6_6.7.i686.rpm
    glibc-common-2.12-1.149.el6_6.7.i686.rpm
    glibc-debuginfo-2.12-1.149.el6_6.7.i686.rpm
    glibc-debuginfo-common-2.12-1.149.el6_6.7.i686.rpm
    glibc-devel-2.12-1.149.el6_6.7.i686.rpm
    glibc-headers-2.12-1.149.el6_6.7.i686.rpm
    glibc-utils-2.12-1.149.el6_6.7.i686.rpm
    nscd-2.12-1.149.el6_6.7.i686.rpm
    glibc-static-2.12-1.149.el6_6.7.i686.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2