Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in the GNU C Library.
Software Description:
- glibc: GNU C Library
- eglibc: GNU C Library
Details:
Martin Carpenter discovered that pt_chown in the GNU C Library did not
properly check permissions for tty files. A local attacker could use this
to gain administrative privileges or expose sensitive information.
(CVE-2013-2207, CVE-2016-2856)
Robin Hack discovered that the Name Service Switch (NSS) implementation in
the GNU C Library did not properly manage its file descriptors. An attacker
could use this to cause a denial of service (infinite loop).
(CVE-2014-8121)
Joseph Myers discovered that the GNU C Library did not properly handle long
arguments to functions returning a representation of Not a Number (NaN). An
attacker could use this to cause a denial of service (stack exhaustion
leading to an application crash) or possibly execute arbitrary code.
(CVE-2014-9761)
Arjun Shankar discovered that in certain situations...
The problem can be corrected by updating your system to the following package versions: Ubuntu 15.10: libc6 2.21-0ubuntu4.2 libc6-dev 2.21-0ubuntu4.2 Ubuntu 14.04 LTS: libc6 2.19-0ubuntu6.8 libc6-dev 2.19-0ubuntu6.8 Ubuntu 12.04 LTS: libc6 2.15-0ubuntu10.14 libc6-dev 2.15-0ubuntu10.14 After a standard system update you need to reboot your computer to make all the necessary changes.
https://ubuntu.com/security/notices/USN-2985-1
CVE-2013-2207, CVE-2014-8121, CVE-2014-9761, CVE-2015-1781,
CVE-2015-5277, CVE-2015-8776, CVE-2015-8777, CVE-2015-8778,
CVE-2015-8779, CVE-2016-2856, CVE-2016-3075
Get the latest Linux and open source security news straight to your inbox.