The xdrmem_getbytes() function in the XDR library provided by Sun Microsystems contains an integer overflow.. - - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200303-29 - - --------------------------------------------------------------------- PACKAGE : dietlibc SUMMARY : integer overflow DATE : 2003-03-31 12:35 UTC EXPLOIT : remote VERSIONS AFFECTED : =0.22-r1 CVE : CAN-2003-0028 - - --------------------------------------------------------------------- - From advisory: "The xdrmem_getbytes() function in the XDR library provided by Sun Microsystems contains an integer overflow. Depending on the location and use of the vulnerable xdrmem_getbytes() routine, various conditions may be presented that can permit an attacker to remotely exploit a service using this vulnerable routine." Read the full advisory at: Privileged Access Management, Cyber Security, and… | BeyondTrust SOLUTION It is recommended that all Gentoo Linux users who are running dev-libs/dietlibc upgrade to dietlibc-0.22-r1 as follows: emerge sync emerge dietlibc emerge clean - - ---------------------------------------------------------------------
There is an integer overflow in the xdrmem_getbytes() function of glibc, that is also present in dietlibc.. - -------------------------------------------------------------------------- Debian Security Advisory DSA 272-1
The upstream author of dietlibc, Felix von Leitner, discovered a potential division by zero chance in the fwrite and calloc integer overflow checks.. - -------------------------------------------------------------------------- Debian Security Advisory DSA 146-2
An integer overflow bug has been discovered in the RPC library used bydietlibc, which could be exploited to gain unauthorized root access to software linking to this code.. - -------------------------------------------------------------------------- Debian Security Advisory DSA 146-1
Get the latest Linux and open source security news straight to your inbox.