Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Debian: DSA-3169-1 Moderate: eglibc Denial of Service Advisory

debian
Calendar Grey February 23, 2015
Debian Logo
Ubuntu's Security Notice USN-4120-1 enhances libssl, correcting various severe vulnerabilities and bolstering system integrity.
Several vulnerabilities have been fixed in eglibc, Debian's version of the GNU C library: CVE-2012-3406

Summary

Several vulnerabilities have been fixed in eglibc, Debian's version of
the GNU C library:

CVE-2012-3406
The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka
glibc) 2.5, 2.12, and probably other versions does not "properly restrict
the use of" the alloca function when allocating the SPECS array, which
allows context-dependent attackers to bypass the FORTIFY_SOURCE
format-string protection mechanism and cause a denial of service (crash)
or possibly execute arbitrary code via a crafted format string using
positional parameters and a large number of format specifiers, a different
vulnerability than CVE-2012-3404 and CVE-2012-3405.

CVE-2013-7424
An invalid free flaw was found in glibc's getaddrinfo() function when used
with the AI_IDN flag. A remote attacker able to make an application call
this function could use this flaw to execute arbitrary code with the
permissions of the user running the application. Note that this flaw only
aff...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Package: eglibc
CVE ID: CVE-2012-3406 CVE-2013-7424 CVE-2014-4043 CVE-2014-9402

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here