An update that solves four vulnerabilities and has one An update that solves four vulnerabilities and has one An update that solves four vulnerabilities and has one errata is now available. errata is now available.. SUSE Security Update: Security update for glibc ______________________________________________________________________________ Announcement ID: SUSE-SU-2014:1129-1 Rating: important References: #836746 #844309 #892073 #894553 #894556 Cross-References: CVE-2012-6656 CVE-2013-4357 CVE-2014-5119 CVE-2014-6040 Affected Products: SUSE Linux Enterprise Server 11 SP2 LTSS ______________________________________________________________________________ An update that solves four vulnerabilities and has one errata is now available. Description: This glibc update fixes a critical privilege escalation problem and two additional issues: * bnc#892073: An off-by-one error leading to a heap-based buffer overflow was found in __gconv_translit_find(). An exploit that targets the problem is publicly available. (CVE-2014-5119) * bnc#836746: Avoid race between {, __de}allocate_stack and __reclaim_stacks during fork. * bnc#844309: Fixed various overflows, reading large /etc/hosts or long names. (CVE-2013-4357) * bnc#894553, bnc#894556: Fixed various crashes on invalid input in IBM gconv modules. (CVE-2014-6040, CVE-2012-6656) Security Issues: * CVE-2012-6656 * CVE-2013-4357 * CVE-2014-5119 * CVE-2014-6040 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11 SP2 LTSS: zypper in -t patch slessp2-glibc-9721 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server 11 SP2 LTSS (i586 i686 s390x x86_64): glibc-2.11.3-17.45.53.1 glibc-devel-2.11.3-17.45.53.1 - SUSE Linux Enterprise Server 11 SP2 LTSS (i586 s390x x86_64): glibc-html-2.11.3-17.45.53.1 glibc-i18ndata-2.11.3-17.45.53.1 glibc-info-2.11.3-17.45.53.1 glibc-locale-2.11.3-17.45.53.1 glibc-profile-2.11.3-17.45.53.1 nscd-2.11.3-17.45.53.1 - SUSE Linux Enterprise Server 11 SP2 LTSS (s390x x86_64): glibc-32bit-2.11.3-17.45.53.1 glibc-devel-32bit-2.11.3-17.45.53.1 glibc-locale-32bit-2.11.3-17.45.53.1 glibc-profile-32bit-2.11.3-17.45.53.1 References: https://www.suse.com/security/cve/CVE-2012-6656.html https://www.suse.com/security/cve/CVE-2013-4357.html https://www.suse.com/security/cve/CVE-2014-5119.html https://www.suse.com/security/cve/CVE-2014-6040.html https://scc.suse.com:443/patches/ . Canonical Security Patch addresses severe flaws in systemd, bolstering operational security and mitigating risks.. glibc Update,SUSE Linux Update,Security Patch,Buffer Overflow Fix. . Severity: Important. LinuxSecurity.com Team
New bind packages are available for Slackware 8.1, 9.0, 9.1, 10.0, 10.1, 10.2, 11.0, 12.0, 12.1, 12.2, and -current to fix a security issue. More details about this issue may be found in the Common Vulnerabilities and Exposures (CVE) database: . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] bind (SSA:2009-210-01) New bind packages are available for Slackware 8.1, 9.0, 9.1, 10.0, 10.1, 10.2, 11.0, 12.0, 12.1, 12.2, and -current to fix a security issue. More details about this issue may be found in the Common Vulnerabilities and Exposures (CVE) database: https://www.cve.org/CVERecord?id=CVE-2009-0696 ISC has published an announcement here: And CERT has published an advisory here: http://www.kb.cert.org/vuls/id/725188 Here are the details from the Slackware 12.2 ChangeLog: +--------------------------+ patches/packages/bind-9.4.3_P3-i486-1_slack12.2.tgz: Upgraded. This BIND update fixes a security problem where a specially crafted dynamic update message packet will cause named to exit resulting in a denial of service. An active remote exploit is in wide circulation at this time. For more information, see: https://www.cve.org/CVERecord?id=CVE-2009-0696 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ HINT: Getting slow download speeds from ftp.slackware.com? Give slackware.osuosl.org a try. This is another primary FTP site for Slackware that can be considerably faster than downloading directly from ftp.slackware.com. Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating additional FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 8.1: Updated package for Slackware 9.0: Updated package for Slackware 9.1: Updated package for Slackware 10.0: Updated package for Slackware 10.1: Updated package for Slackware10.2: Updated package for Slackware 11.0: Updated package for Slackware 12.0: Updated package for Slackware 12.1: Updated package for Slackware 12.2: Updated package for Slackware -current: Updated package for Slackware64 -current: MD5 signatures: +-------------+ Slackware 8.1 package: a80dcb15eb2b64cbbb74094a14cf43ce bind-9.4.3_P3-i386-1_slack8.1.tgz Slackware 9.0 package: 5f076dd18643481aa7ac05d0e5f842c9 bind-9.4.3_P3-i386-1_slack9.0.tgz Slackware 9.1 package: d6c317bc01909ffd59b27510a3d3e00a bind-9.4.3_P3-i486-1_slack9.1.tgz Slackware 10.0 package: 31d34b00234299cb43adc06a8e5f0ea5 bind-9.4.3_P3-i486-1_slack10.0.tgz Slackware 10.1 package: 5c52f3896416ff260eedbf625db2f0a0 bind-9.4.3_P3-i486-1_slack10.1.tgz Slackware 10.2 package: cc4a9d222077cc66ef42f46b94ef999b bind-9.4.3_P3-i486-1_slack10.2.tgz Slackware 11.0 package: a7eae43c7dbacb05ca5b5968926713da bind-9.4.3_P3-i486-1_slack11.0.tgz Slackware 12.0 package: c52604266a652e08173ace69c8676775 bind-9.4.3_P3-i486-1_slack12.0.tgz Slackware 12.1 package: dc2c7ee229176f17159a36b426eb76b7 bind-9.4.3_P3-i486-1_slack12.1.tgz Slackware 12.2 package: 0a438a7403bd82d331f1484a73f6b92b bind-9.4.3_P3-i486-1_slack12.2.tgz Slackware -current package: a3c9df7a63ca906aab873ab1c75b797d bind-9.4.3_P3-i486-1.txz Slackware64 -current package: 17910d0674e4fbf9d364a599a86a8ab6 bind-9.4.3_P3-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg bind-9.4.3_P3-i486-1_slack12.2.tgz Then, restart bind: /etc/rc.d/rc.bind restart +-----+ . Updated bind distributions released for Slackware to resolve a significant denial of service vulnerability impacting various releases.. Bind Packages, Slackware Security, Exploit Patch, Denial Of Service, System Upgrade. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.