[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247621

 
 

909

 
 

194512

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CESA-2017:0680 -- centos 6 glibc

ID: oval:org.secpod.oval:def:204635Date: (C)2018-04-30   (M)2023-07-28
Class: PATCHFamily: unix




The glibc packages provide the standard C libraries , POSIX thread libraries , standard math libraries , and the name service cache daemon used by multiple programs on the system. Without these libraries, the Linux system cannot function correctly. Security Fix: * A stack overflow vulnerability was found in nan* functions that could cause applications, which process long strings with the nan function, to crash or, potentially, execute arbitrary code. * It was found that out-of-range time values passed to the strftime function could result in an out-of-bounds memory access. This could lead to application crash or, potentially, information disclosure. * An integer overflow vulnerability was found in hcreate and hcreate_r functions which could result in an out-of-bounds memory access. This could lead to application crash or, potentially, arbitrary code execution. * A stack based buffer overflow vulnerability was found in the catopen function. An excessively long string passed to the function could cause it to crash or, potentially, execute arbitrary code. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 6.9 Release Notes and Red Hat Enterprise Linux 6.9 Technical Notes linked from the References section.

Platform:
CentOS 6
Product:
glibc
nscd
Reference:
CESA-2017:0680
CVE-2014-9761
CVE-2015-8776
CVE-2015-8778
CVE-2015-8779
CVE    4
CVE-2014-9761
CVE-2015-8778
CVE-2015-8779
CVE-2015-8776
...
CPE    2
cpe:/a:glibc:glibc
cpe:/o:centos:centos:6

© SecPod Technologies