Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.51041
Category:Red Hat Local Security Checks
Title:RedHat Security Advisory RHSA-2004:383
Summary:NOSUMMARY
Description:Description:

The remote host is missing updates announced in
advisory RHSA-2004:383.

The GNU libc packages (known as glibc) contain the standard C libraries
used by applications.

A security audit of the glibc packages in Red Hat Enterprise Linux 2.1
found a flaw in the resolver library which was originally reported as
affecting versions of ISC BIND 4.9. This flaw also applied to glibc
versions before 2.3.2. An attacker who is able to send DNS responses
(perhaps by creating a malicious DNS server) could remotely exploit this
vulnerability to execute arbitrary code or cause a denial of service. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CVE-2002-0029 to this issue.

These updated packages also fix a dlclose function bug on certain shared
libraries, which caused program crashes.

All users of glibc should upgrade to these updated packages, which
resolve these issues.

Solution:
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

http://rhn.redhat.com/errata/RHSA-2004-383.html
http://www.kb.cert.org/vuls/id/844360

Risk factor : High

CVSS Score:
7.5

Cross-Ref: BugTraq ID: 6186
Common Vulnerability Exposure (CVE) ID: CVE-2002-0029
http://lists.apple.com/archives/Security-announce/2002/Nov/msg00000.html
http://www.securityfocus.com/bid/6186
http://www.cert.org/advisories/CA-2002-31.html
CERT/CC vulnerability note: VU#844360
http://www.kb.cert.org/vuls/id/844360
NETBSD Security Advisory: NetBSD-SA2002-028
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-028.txt.asc
SGI Security Advisory: 20021201-01-P
ftp://patches.sgi.com/support/free/security/advisories/20021201-01-P
http://www.iss.net/security_center/static/10624.php
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.