Updated glibc packages fix a security vulnerabilities: The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399 encodings, fails to advance the . MGASA-2021-0150 - Updated glibc packages fixes security vulnerabilities Publication date: 21 Mar 2021 URL: https://advisories.mageia.org/MGASA-2021-0150.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-27618, CVE-2021-3326, CVE-2021-27645 Updated glibc packages fix a security vulnerabilities: The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399 encodings, fails to advance the input state, which could lead to an infinite loop in applications, resulting in a denial of service (CVE-2020-27618). The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service (CVE-2021-3326). The nameserver caching daemon (nscd), when processing a request for netgroup lookup, may crash due to a double-free, potentially resulting in degraded service or Denial of Service on the local system (CVE-2021-27645). References: - https://bugs.mageia.org/show_bug.cgi?id=28246 - https://www.cve.org/CVERecord?id=CVE-2020-27618 - https://www.cve.org/CVERecord?id=CVE-2021-3326 - https://www.cve.org/CVERecord?id=CVE-2021-27645 SRPMS: - 7/core/glibc-2.29-22.mga7 . Revised glibc distributions tackle severe vulnerabilities that lead to service interruptions and possible application failures, improving overall security.. Mageia 7 glibc update, security vulnerabilities fix, denial of service, application security. . LinuxSecurity.com Team
Updated glibc packages fix a security vulnerability: The nameserver caching daemon (nscd), when processing a request for netgroup lookup, may crash due to a double-free, potentially resulting in degraded service or Denial of Service on the local system (CVE-2021-27645). . MGASA-2021-0138 - Updated glibc packages fix a security vulnerability Publication date: 17 Mar 2021 URL: https://advisories.mageia.org/MGASA-2021-0138.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-27645 Updated glibc packages fix a security vulnerability: The nameserver caching daemon (nscd), when processing a request for netgroup lookup, may crash due to a double-free, potentially resulting in degraded service or Denial of Service on the local system (CVE-2021-27645). References: - https://bugs.mageia.org/show_bug.cgi?id=28587 - https://www.cve.org/CVERecord?id=CVE-2021-27645 SRPMS: - 8/core/glibc-2.32-15.mga8 . Recently released glibc updates for Mageia tackle significant risks of service interruptions on local machines caused by a vulnerability.. Glibc Update, Mageia Security, Denial of Service, Nscd Vulnerability, March 2021 Advisory. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.