[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250108

 
 

909

 
 

196064

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2021:1585-01 -- Redhat glibc, compat-libpthread-nonshared, libnsl, nscd, nss_db

ID: oval:org.secpod.oval:def:73579Date: (C)2021-07-02   (M)2024-04-17
Class: PATCHFamily: unix




The glibc packages provide the standard C libraries , POSIX thread libraries , standard math libraries , and the name service cache daemon used by multiple programs on the system. Without these libraries, the Linux system cannot function correctly. Security Fix: * glibc: buffer over-read in iconv when processing invalid multi-byte input sequences in the EUC-KR encoding * glibc: regular-expression match via proceed_next_node in posix/regexec.c leads to heap-based buffer over-read * glibc: assertion failure in ISO-2022-JP-3 gconv module related to combining characters * glibc: iconv program can hang when invoked with the -c option * glibc: iconv when processing invalid multi-byte input sequences fails to advance the input state, which could result in an infinite loop For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.4 Release Notes linked from the References section.

Platform:
CentOS 8
Product:
glibc
compat-libpthread-nonshared
libnsl
nscd
nss_db
Reference:
RHSA-2021:1585-01
CVE-2016-10228
CVE-2019-9169
CVE-2019-25013
CVE-2020-27618
CVE-2021-3326
CVE    5
CVE-2016-10228
CVE-2019-9169
CVE-2021-3326
CVE-2020-27618
...
CPE    6
cpe:/a:compat-libpthread-nonshared:compat-libpthread-nonshared
cpe:/a:glibc:glibc
cpe:/o:centos:centos:8
cpe:/a:piotr_roszatycki:nss-db
...

© SecPod Technologies