[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3142-1 eglibc -- eglibc

ID: oval:org.secpod.oval:def:601934Date: (C)2015-01-28   (M)2024-02-19
Class: PATCHFamily: unix




Several vulnerabilities have been fixed in eglibc, Debian"s version of the GNU C library: CVE-2015-0235 Qualys discovered that the gethostbyname and gethostbyname2 functions were subject to a buffer overflow if provided with a crafted IP address argument. This could be used by an attacker to execute arbitrary code in processes which called the affected functions. The original glibc bug was reported by Peter Klotz. CVE-2014-7817 Tim Waugh of Red Hat discovered that the WRDE_NOCMD option of the wordexp function did not suppress command execution in all cases. This allows a context-dependent attacker to execute shell commands. CVE-2012-6656 CVE-2014-6040 The charset conversion code for certain IBM multi-byte code pages could perform an out-of-bounds array access, causing the process to crash. In some scenarios, this allows a remote attacker to cause a persistent denial of service.

Platform:
Debian 7.0
Product:
eglibc-source
Reference:
DSA-3142-1
CVE-2012-6656
CVE-2014-6040
CVE-2014-7817
CVE-2015-0235
CVE    4
CVE-2014-6040
CVE-2014-7817
CVE-2012-6656
CVE-2015-0235
...
CPE    2
cpe:/o:debian:debian_linux:7.x
cpe:/a:gnu:eglibc

© SecPod Technologies