Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.10.2018.0293
Category:Mageia Linux Local Security Checks
Title:Mageia: Security Advisory (MGASA-2018-0293)
Summary:The remote host is missing an update for the 'glibc' package(s) announced via the MGASA-2018-0293 advisory.
Description:Summary:
The remote host is missing an update for the 'glibc' package(s) announced via the MGASA-2018-0293 advisory.

Vulnerability Insight:
Updated glibc packages fix security vulnerabilities:

An SSE2-optimized memmove implementation for i386 in
sysdeps/i386/i686/multiarch/memcpy-sse2-unaligned.S in the GNU C Library (aka
glibc or libc6) 2.21 through 2.27 does not correctly perform the overlapping
memory check if the source memory range spans the middle of the address space,
resulting in corrupt data being produced by the copy operation. This may
disclose information to context-dependent attackers, or result in a denial of
service, or, possibly, code execution (CVE-2017-18269).

stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and
earlier, when processing very long pathname arguments to the realpath function,
could encounter an integer overflow on 32-bit architectures, leading to a
stack-based buffer overflow and, potentially, arbitrary code execution
(CVE-2018-11236).

Affected Software/OS:
'glibc' package(s) on Mageia 6.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2017-18269
https://github.com/fingolfin/memmove-bug
https://sourceware.org/bugzilla/show_bug.cgi?id=22644
https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=cd66c0e584c6d692bc8347b5e72723d02b8a8ada
https://usn.ubuntu.com/4416-1/
Common Vulnerability Exposure (CVE) ID: CVE-2018-11236
BugTraq ID: 104255
http://www.securityfocus.com/bid/104255
https://sourceware.org/bugzilla/show_bug.cgi?id=22786
https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=5460617d1567657621107d895ee2dd83bc1f88f2
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
RedHat Security Advisories: RHBA-2019:0327
https://access.redhat.com/errata/RHBA-2019:0327
RedHat Security Advisories: RHSA-2018:3092
https://access.redhat.com/errata/RHSA-2018:3092
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.