Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Ubuntu 14.04 LTS: 6762-1 Critical eglibc Denial of Service Attack

ubuntu
Calendar Grey May 2, 2024
Dist Ubuntu Esm H88
Recent security bulletins for GNULibC have highlighted severe vulnerabilities that necessitate prompt updates to ensure defenses against potential exploits.
Several security issues were fixed in GNU C Library.

Summary

A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in GNU C Library. Software Description: - glibc: GNU C Library - eglibc: GNU C Library Details: It was discovered that GNU C Library incorrectly handled netgroup requests. An attacker could possibly use this issue to cause a crash or execute arbitrary code. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-9984) It was discovered that GNU C Library might allow context-dependent attackers to cause a denial of service. This issue only affected Ubuntu 14.04 LTS. (CVE-2015-20109) It was discovered that GNU C Library when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures, leading to a stack-based buffer overflow and, potentially, arbitrary code execution. This issue only affected Ubuntu 14.04 LTS. (CVE-2018-11236) It was discovered...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS libc6 2.27-3ubuntu1.6+esm2 Available with Ubuntu Pro Ubuntu 16.04 LTS libc6 2.23-0ubuntu11.3+esm6 Available with Ubuntu Pro Ubuntu 14.04 LTS libc6 2.19-0ubuntu6.15+esm3 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-6762-1

CVE-2014-9984, CVE-2015-20109, CVE-2018-11236, CVE-2021-3999,

CVE-2024-2961, https://bugs.launchpad.net/ubuntu/+source/eglibc/+bug/2063328

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-6762-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here