Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu 13.04: USN-1991-1 Moderate: eglibc Denial Of Service Vulnerability

ubuntu
Calendar Grey October 21, 2013
Scroller Ubuntu
Several vulnerabilities addressed in the GNU C Library, impacting various Ubuntu versions. Guidance for updates included.
Several security issues were fixed in the GNU C Library.

Summary

Several security issues were fixed in the GNU C Library.

Software Description:

- eglibc: GNU C Library

Details:

It was discovered that the GNU C Library incorrectly handled the strcoll()

function. An attacker could use this issue to cause a denial of service, or

possibly execute arbitrary code. (CVE-2012-4412, CVE-2012-4424)

It was discovered that the GNU C Library incorrectly handled multibyte

characters in the regular expression matcher. An attacker could use this

issue to cause a denial of service. (CVE-2013-0242)

It was discovered that the GNU C Library incorrectly handled large numbers

of domain conversion results in the getaddrinfo() function. An attacker

could use this issue to cause a denial of service. (CVE-2013-1914)

It was discovered that the GNU C Library readdir_r() function incorrectly

handled crafted NTFS or CIFS images. An attacker could use this issue to

cause a denial of service, or possibly execute arbitrary code.

(CVE-2013-4237)

I...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
  libc6                           2.17-0ubuntu5.1

Ubuntu 12.10:
  libc6                           2.15-0ubuntu20.2

Ubuntu 12.04 LTS:
  libc6                           2.15-0ubuntu10.5

Ubuntu 10.04 LTS:
  libc6                           2.11.1-0ubuntu7.13

After a standard system update you need to reboot your computer to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1991-1

CVE-2012-4412, CVE-2012-4424, CVE-2013-0242, CVE-2013-1914,

CVE-2013-4237, CVE-2013-4332

October 21, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.