Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Ubuntu 10.04 LTS: USN-2306-3 Moderate eglibc Denial of Service Fix

ubuntu
Calendar Grey September 8, 2014
Scroller Ubuntu
Uncover the issue with OpenSSL in Ubuntu 18.04 LTS resolved by USN-4124-1, impacting security and performance.
USN-2306-1 introduced a regression in the GNU C Library.

Summary

USN-2306-1 introduced a regression in the GNU C Library.

Software Description:

- eglibc: GNU C Library

Details:

USN-2306-1 fixed vulnerabilities in the GNU C Library. On Ubuntu 10.04 LTS,

the fix for CVE-2013-4357 introduced a memory leak in getaddrinfo. This

update fixes the problem.

We apologize for the inconvenience.

Original advisory details:

Maksymilian Arciemowicz discovered that the GNU C Library incorrectly

handled the getaddrinfo() function. An attacker could use this issue to

cause a denial of service. This issue only affected Ubuntu 10.04 LTS.

(CVE-2013-4357)

It was discovered that the GNU C Library incorrectly handled the

getaddrinfo() function. An attacker could use this issue to cause a denial

of service. This issue only affected Ubuntu 10.04 LTS and Ubuntu 12.04 LTS.

(CVE-2013-4458)

Stephane Chazelas discovered that the GNU C Library incorrectly handled

locale environment variables. An attacker could use this issue to possib...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 10.04 LTS:
  libc6                           2.11.1-0ubuntu7.17

After a standard system update you need to reboot your computer to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2306-3

https://ubuntu.com/security/notices/USN-2306-1

https://bugs.launchpad.net/ubuntu/+source/eglibc/+bug/1364584

September 08, 2014

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.