Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Gentoo: 200303-22 Critical Glibc Remote Exploit Advisory

gentoo
Calendar Grey March 25, 2003
Dist Gentoo Esm H88
The Debian project warns users of a severe memory allocation flaw found in the kernel, which may lead to unauthorized access, prompting immediate system updates to enhance security.
Various conditions may be presented that can permit an attacker to remotelyexploit a service using this vulnerable routine in the XDR library.

Summary


- ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200303-22
- ---------------------------------------------------------------------
    FIXED VERSION : >=2.3.1-r4 (arm: >=2.2.5-r8)

- ---------------------------------------------------------------------
>From advisory:
"The xdrmem_getbytes() function in the XDR library provided by Sun Microsystems contains an integer overflow. Depending on the location and use of the vulnerable xdrmem_getbytes() routine, various conditions may be presented that can permit an attacker to remotely exploit a service using this vulnerable routine."
Read the full advisory at:
SOLUTION
It is recommended that all Gentoo Linux users who are running sys-libs/glibc upgrade to glibc-2.3.1-r4 (arm: glibc-2.2.5-r8) as follows:
emerge sync emerge glibc emerge clean


Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
critical
Lowest
Low
Medium
High
Critical

PACKAGE : glibc
SUMMARY : integer overflow
DATE : 2003-03-25 08:49 UTC
EXPLOIT : remote
VERSIONS AFFECTED : <2.3.1-r4 (arm: <2.2.5-r8)
CVE : CAN-2003-0028

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here