Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu 15.10 USN-2985-1 Critical: Glibc Buffer Overflow Issues

ubuntu
Calendar Grey May 25, 2016
Scroller Ubuntu
A number of security flaws were addressed in the GNU C Library to reduce potential threats and prevent denial of service incidents.
Several security issues were fixed in the GNU C Library.

Summary

Several security issues were fixed in the GNU C Library.

Software Description:

- glibc: GNU C Library

- eglibc: GNU C Library

Details:

Martin Carpenter discovered that pt_chown in the GNU C Library did not

properly check permissions for tty files. A local attacker could use this

to gain administrative privileges or expose sensitive information.

(CVE-2013-2207, CVE-2016-2856)

Robin Hack discovered that the Name Service Switch (NSS) implementation in

the GNU C Library did not properly manage its file descriptors. An attacker

could use this to cause a denial of service (infinite loop).

(CVE-2014-8121)

Joseph Myers discovered that the GNU C Library did not properly handle long

arguments to functions returning a representation of Not a Number (NaN). An

attacker could use this to cause a denial of service (stack exhaustion

leading to an application crash) or possibly execute arbitrary code.

(CVE-2014-9761)

Arjun Shankar discovered that in certain situations...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
  libc6                           2.21-0ubuntu4.2
  libc6-dev                       2.21-0ubuntu4.2

Ubuntu 14.04 LTS:
  libc6                           2.19-0ubuntu6.8
  libc6-dev                       2.19-0ubuntu6.8

Ubuntu 12.04 LTS:
  libc6                           2.15-0ubuntu10.14
  libc6-dev                       2.15-0ubuntu10.14

After a standard system update you need to reboot your computer to
make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2985-1

CVE-2013-2207, CVE-2014-8121, CVE-2014-9761, CVE-2015-1781,

CVE-2015-5277, CVE-2015-8776, CVE-2015-8777, CVE-2015-8778,

CVE-2015-8779, CVE-2016-2856, CVE-2016-3075

Severity
critical
Lowest
Low
Medium
High
Critical

May 25, 2016

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.