CESA-2012:1208 -- centos 6 glibcID: oval:org.secpod.oval:def:202429 | Date: (C)2012-09-27 (M)2023-07-28 |
Class: PATCH | Family: unix |
The glibc packages provide the standard C and standard math libraries used by multiple programs on the system. Without these libraries, the Linux system cannot function properly. Multiple integer overflow flaws, leading to stack-based buffer overflows, were found in glibc"s functions for converting a string to a numeric representation . If an application used such a function on attacker controlled input, it could cause the application to crash or, potentially, execute arbitrary code. All users of glibc are advised to upgrade to these updated packages, which contain a backported patch to correct these issues.