Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Multiple vulnerabilities were discovered and fixed in the GNU C Library.
Software Description:
- eglibc: Embedded GNU C Library: sources
- glibc: GNU C Library: Documentation
Details:
It was discovered that the GNU C Library did not properly handle
integer overflows in the timezone handling code. An attacker could use
this to possibly execute arbitrary code by convincing an application
to load a maliciously constructed tzfile. (CVE-2009-5029)
It was discovered that the GNU C Library did not properly handle
passwd.adjunct.byname map entries in the Network Information Service
(NIS) code in the name service caching daemon (nscd). An attacker
could use this to obtain the encrypted passwords of NIS accounts.
This issue only affected Ubuntu 8.04 LTS. (CVE-2010-0015)
Chris Evans reported that the GNU C Library did not properly
calculate the amount of memory to allocate in the fnmatch() code. An
attacker could use this to cause a denial of service or possibly
execute arbitrary code vi...
The problem can be corrected by updating your system to the following package versions: Ubuntu 11.10: libc6 2.13-20ubuntu5.1 Ubuntu 11.04: libc6 2.13-0ubuntu13.1 Ubuntu 10.10: libc-bin 2.12.1-0ubuntu10.4 libc6 2.12.1-0ubuntu10.4 Ubuntu 10.04 LTS: libc-bin 2.11.1-0ubuntu7.10 libc6 2.11.1-0ubuntu7.10 Ubuntu 8.04 LTS: libc6 2.7-10ubuntu8.1 After a standard system update you need to restart all services or reboot your computer to make all the necessary changes.
https://ubuntu.com/security/notices/USN-1396-1
CVE-2009-5029, CVE-2010-0015, CVE-2011-1071, CVE-2011-1089,
CVE-2011-1095, CVE-2011-1658, CVE-2011-1659, CVE-2011-2702,
CVE-2011-4609, CVE-2012-0864
Get the latest Linux and open source security news straight to your inbox.