Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Ubuntu 11.10 USN-1396-1 Moderate: Glibc Integer Overflow Issues

ubuntu
Calendar Grey March 9, 2012
Scroller Ubuntu
Tackle various security flaws in GNU C Library as indicated in Ubuntu Security Notice USN-1396-1. An upgrade is advised.
Multiple vulnerabilities were discovered and fixed in the GNU C Library.

Summary

Multiple vulnerabilities were discovered and fixed in the GNU C Library.

Software Description:

- eglibc: Embedded GNU C Library: sources

- glibc: GNU C Library: Documentation

Details:

It was discovered that the GNU C Library did not properly handle

integer overflows in the timezone handling code. An attacker could use

this to possibly execute arbitrary code by convincing an application

to load a maliciously constructed tzfile. (CVE-2009-5029)

It was discovered that the GNU C Library did not properly handle

passwd.adjunct.byname map entries in the Network Information Service

(NIS) code in the name service caching daemon (nscd). An attacker

could use this to obtain the encrypted passwords of NIS accounts.

This issue only affected Ubuntu 8.04 LTS. (CVE-2010-0015)

Chris Evans reported that the GNU C Library did not properly

calculate the amount of memory to allocate in the fnmatch() code. An

attacker could use this to cause a denial of service or possibly

execute arbitrary code vi...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
  libc6                           2.13-20ubuntu5.1

Ubuntu 11.04:
  libc6                           2.13-0ubuntu13.1

Ubuntu 10.10:
  libc-bin                        2.12.1-0ubuntu10.4
  libc6                           2.12.1-0ubuntu10.4

Ubuntu 10.04 LTS:
  libc-bin                        2.11.1-0ubuntu7.10
  libc6                           2.11.1-0ubuntu7.10

Ubuntu 8.04 LTS:
  libc6                           2.7-10ubuntu8.1

After a standard system update you need to restart all services or
reboot your computer to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1396-1

CVE-2009-5029, CVE-2010-0015, CVE-2011-1071, CVE-2011-1089,

CVE-2011-1095, CVE-2011-1658, CVE-2011-1659, CVE-2011-2702,

CVE-2011-4609, CVE-2012-0864

March 09, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.