Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.71726
Category:Ubuntu Local Security Checks
Title:Ubuntu USN-1396-1 (libc6)
Summary:NOSUMMARY
Description:Description:
The remote host is missing an update to libc6
announced via advisory USN-1396-1.

Details:

It was discovered that the GNU C Library did not properly handle
integer overflows in the timezone handling code. An attacker could use
this to possibly execute arbitrary code by convincing an application
to load a maliciously constructed tzfile. (CVE-2009-5029)

It was discovered that the GNU C Library did not properly handle
passwd.adjunct.byname map entries in the Network Information Service
(NIS) code in the name service caching daemon (nscd). An attacker
could use this to obtain the encrypted passwords of NIS accounts.
This issue only affected Ubuntu 8.04 LTS. (CVE-2010-0015)

Chris Evans reported that the GNU C Library did not properly
calculate the amount of memory to allocate in the fnmatch() code. An
attacker could use this to cause a denial of service or possibly
execute arbitrary code via a maliciously crafted UTF-8 string.
This issue only affected Ubuntu 8.04 LTS, Ubuntu 10.04 LTS and Ubuntu
10.10. (CVE-2011-1071)

Tomas Hoger reported that an additional integer overflow was possible
in the GNU C Library fnmatch() code. An attacker could use this to
cause a denial of service via a maliciously crafted UTF-8 string. This
issue only affected Ubuntu 8.04 LTS, Ubuntu 10.04 LTS, Ubuntu 10.10
and Ubuntu 11.04. (CVE-2011-1659)

Dan Rosenberg discovered that the addmntent() function in the GNU C
Library did not report an error status for failed attempts to write to
the /etc/mtab file. This could allow an attacker to corrupt /etc/mtab,
possibly causing a denial of service or otherwise manipulate mount
options. This issue only affected Ubuntu 8.04 LTS, Ubuntu 10.04 LTS,
Ubuntu 10.10 and Ubuntu 11.04. (CVE-2011-1089)

Harald van Dijk discovered that the locale program included with the
GNU C library did not properly quote its output. This could allow a
local attacker to possibly execute arbitrary code using a crafted
localization string that was evaluated in a shell script. This
issue only affected Ubuntu 8.04 LTS, Ubuntu 10.04 LTS and Ubuntu
10.10. (CVE-2011-1095)

It was discovered that the GNU C library loader expanded the
$ORIGIN dynamic string token when RPATH is composed entirely of this
token. This could allow an attacker to gain privilege via a setuid
program that had this RPATH value. (CVE-2011-1658)

It was discovered that the GNU C library implementation of memcpy
optimized for Supplemental Streaming SIMD Extensions 3 (SSSE3)
contained a possible integer overflow. An attacker could use this to
cause a denial of service or possibly execute arbitrary code. This
issue only affected Ubuntu 10.04 LTS. (CVE-2011-2702)

John Zimmerman discovered that the Remote Procedure Call (RPC)
implementation in the GNU C Library did not properly handle large
numbers of connections. This could allow a remote attacker to cause
a denial of service. (CVE-2011-4609)

It was discovered that the GNU C Library vfprintf() implementation
contained a possible integer overflow in the format string protection
code offered by FORTIFY_SOURCE. An attacker could use this flaw in
conjunction with a format string vulnerability to bypass the format
string protection and possibly execute arbitrary code. (CVE-2012-0864)

Solution:
The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
libc6 2.13-20ubuntu5.1

Ubuntu 11.04:
libc6 2.13-0ubuntu13.1

Ubuntu 10.10:
libc-bin 2.12.1-0ubuntu10.4
libc6 2.12.1-0ubuntu10.4

Ubuntu 10.04 LTS:
libc-bin 2.11.1-0ubuntu7.10
libc6 2.11.1-0ubuntu7.10

Ubuntu 8.04 LTS:
libc6 2.7-10ubuntu8.1

http://www.securityspace.com/smysecure/catid.html?in=USN-1396-1

CVSS Score:
7.5

CVSS Vector:
AV:L/AC:L/Au:NR/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-5029
20111203 VSFTPD Remote Heap Overrun (low severity)
http://lists.grok.org.uk/pipermail/full-disclosure/2011-December/084452.html
[libc-alpha] 20111215 integer overflow to heap overrun exploit in glibc
http://sourceware.org/ml/libc-alpha/2011-12/msg00037.html
http://dividead.wordpress.com/2009/06/01/glibc-timezone-integer-overflow/
http://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=97ac2654b2d831acaa18a2b018b0736245903fd2
https://bugzilla.redhat.com/show_bug.cgi?id=761245
Common Vulnerability Exposure (CVE) ID: CVE-2010-0015
MDVSA-2010:111
http://www.mandriva.com/security/advisories?name=MDVSA-2010:111
MDVSA-2010:112
http://www.mandriva.com/security/advisories?name=MDVSA-2010:112
SUSE-SA:2010:052
https://lists.opensuse.org/opensuse-security-announce/2010-10/msg00007.html
[oss-security] 20100107 CVE id request: GNU libc: NIS shadow password leakage
http://www.openwall.com/lists/oss-security/2010/01/07/3
[oss-security] 20100108 Re: CVE id request: GNU libc: NIS shadow password leakage
http://www.openwall.com/lists/oss-security/2010/01/08/1
[oss-security] 20100109 Re: CVE id request: GNU libc: NIS shadow password leakage
http://www.openwall.com/lists/oss-security/2010/01/08/2
[oss-security] 20100111 Re: CVE id request: GNU libc: NIS shadow password leakage
http://marc.info/?l=oss-security&m=126320356003425&w=2
http://marc.info/?l=oss-security&m=126320570505651&w=2
http://www.openwall.com/lists/oss-security/2010/01/11/6
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560333
http://sourceware.org/bugzilla/show_bug.cgi?id=11134
http://svn.debian.org/viewsvn/pkg-glibc/glibc-package/trunk/debian/patches/any/submitted-nis-shadow.diff?revision=4062&view=markup
Common Vulnerability Exposure (CVE) ID: CVE-2011-1071
1025290
http://securitytracker.com/id?1025290
20110224 glibc and alloca()
http://seclists.org/fulldisclosure/2011/Feb/635
20110226 Re: glibc and alloca()
http://seclists.org/fulldisclosure/2011/Feb/644
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console
http://www.securityfocus.com/archive/1/520102/100/0/threaded
43492
http://secunia.com/advisories/43492
43830
http://secunia.com/advisories/43830
43989
http://secunia.com/advisories/43989
46397
http://secunia.com/advisories/46397
46563
http://www.securityfocus.com/bid/46563
8175
http://securityreason.com/securityalert/8175
ADV-2011-0863
http://www.vupen.com/english/advisories/2011/0863
MDVSA-2011:178
http://www.mandriva.com/security/advisories?name=MDVSA-2011:178
RHSA-2011:0412
http://www.redhat.com/support/errata/RHSA-2011-0412.html
RHSA-2011:0413
http://www.redhat.com/support/errata/RHSA-2011-0413.html
[oss-security] 20110228 Re: cve request: eglibc memory corruption
http://openwall.com/lists/oss-security/2011/02/28/11
http://openwall.com/lists/oss-security/2011/02/28/15
[oss-security] 20110228 cve request: eglibc memory corruption
http://openwall.com/lists/oss-security/2011/02/26/3
http://bugs.debian.org/615120
http://code.google.com/p/chromium/issues/detail?id=48733
http://scarybeastsecurity.blogspot.com/2011/02/i-got-accidental-code-execution-via.html
http://sourceware.org/bugzilla/show_bug.cgi?id=11883
http://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=f15ce4d8dc139523fe0c273580b604b2453acba6
http://www.vmware.com/security/advisories/VMSA-2011-0012.html
https://bugzilla.redhat.com/show_bug.cgi?id=681054
oval:org.mitre.oval:def:12853
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12853
Common Vulnerability Exposure (CVE) ID: CVE-2011-1659
Bugtraq: 20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (Google Search)
http://www.mandriva.com/security/advisories?name=MDVSA-2011:179
http://www.securitytracker.com/id?1025450
http://secunia.com/advisories/44353
XForce ISS Database: gnuclibrary-fnmatch-dos(66819)
https://exchange.xforce.ibmcloud.com/vulnerabilities/66819
Common Vulnerability Exposure (CVE) ID: CVE-2011-1089
46740
http://www.securityfocus.com/bid/46740
MDVSA-2011:179
RHSA-2011:1526
http://www.redhat.com/support/errata/RHSA-2011-1526.html
[oss-security] 20110303 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
http://openwall.com/lists/oss-security/2011/03/04/11
[oss-security] 20110303 Suid mount helpers fail to anticipate RLIMIT_FSIZE
http://openwall.com/lists/oss-security/2011/03/04/9
[oss-security] 20110304 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
http://openwall.com/lists/oss-security/2011/03/04/10
http://openwall.com/lists/oss-security/2011/03/04/12
[oss-security] 20110305 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
http://openwall.com/lists/oss-security/2011/03/05/3
http://openwall.com/lists/oss-security/2011/03/05/7
[oss-security] 20110307 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
http://openwall.com/lists/oss-security/2011/03/07/9
[oss-security] 20110314 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
http://openwall.com/lists/oss-security/2011/03/14/16
http://openwall.com/lists/oss-security/2011/03/14/5
http://openwall.com/lists/oss-security/2011/03/14/7
[oss-security] 20110315 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
http://openwall.com/lists/oss-security/2011/03/15/6
[oss-security] 20110322 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
http://openwall.com/lists/oss-security/2011/03/22/4
http://openwall.com/lists/oss-security/2011/03/22/6
[oss-security] 20110331 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
http://openwall.com/lists/oss-security/2011/03/31/3
http://openwall.com/lists/oss-security/2011/03/31/4
[oss-security] 20110401 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
http://openwall.com/lists/oss-security/2011/04/01/2
http://sourceware.org/bugzilla/show_bug.cgi?id=12625
https://bugzilla.redhat.com/show_bug.cgi?id=688980
Common Vulnerability Exposure (CVE) ID: CVE-2011-1095
1025286
http://securitytracker.com/id?1025286
43976
http://secunia.com/advisories/43976
GLSA-201011-01
http://security.gentoo.org/glsa/glsa-201011-01.xml
[oss-security] 20110308 Re: glibc locale escaping issue
http://openwall.com/lists/oss-security/2011/03/08/21
http://openwall.com/lists/oss-security/2011/03/08/22
[oss-security] 20110308 glibc locale escaping issue
http://openwall.com/lists/oss-security/2011/03/08/8
http://bugs.gentoo.org/show_bug.cgi?id=330923
http://sources.redhat.com/bugzilla/show_bug.cgi?id=11904
http://sourceware.org/bugzilla/show_bug.cgi?id=11904
http://sourceware.org/git/?p=glibc.git%3Ba=patch%3Bh=026373745eab50a683536d950cb7e17dc98c4259
https://bugzilla.redhat.com/show_bug.cgi?id=625893
oval:org.mitre.oval:def:12272
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12272
Common Vulnerability Exposure (CVE) ID: CVE-2011-1658
http://sourceware.org/bugzilla/show_bug.cgi?id=12393
https://bugzilla.redhat.com/show_bug.cgi?id=667974
XForce ISS Database: gnuclibrary-ldso-priv-esc(66820)
https://exchange.xforce.ibmcloud.com/vulnerabilities/66820
Common Vulnerability Exposure (CVE) ID: CVE-2011-2702
80718
http://www.osvdb.org/80718
[oss-security] 20110718 CVE id request: (e)glibc
http://seclists.org/oss-sec/2011/q3/123
[oss-security] 20110720 Re: CVE id request: (e)glibc
http://seclists.org/oss-sec/2011/q3/153
http://www.eglibc.org/cgi-bin/viewvc.cgi/trunk/libc/ChangeLog?view=markup&pathrev=10032
http://www.nodefense.org/eglibc.txt
http://xorl.wordpress.com/2011/08/06/cve-2011-2702-eglibc-and-glibc-signedness-issue/
https://bugzilla.novell.com/show_bug.cgi?id=706915
https://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=a0ac24d98ace90d1ccba6a2f3e7d55600f2fdb6e
Common Vulnerability Exposure (CVE) ID: CVE-2011-4609
https://bugzilla.redhat.com/show_bug.cgi?id=767299
Common Vulnerability Exposure (CVE) ID: CVE-2012-0864
52201
http://www.securityfocus.com/bid/52201
RHSA-2012:0393
http://rhn.redhat.com/errata/RHSA-2012-0393.html
RHSA-2012:0397
http://rhn.redhat.com/errata/RHSA-2012-0397.html
RHSA-2012:0488
http://rhn.redhat.com/errata/RHSA-2012-0488.html
RHSA-2012:0531
http://rhn.redhat.com/errata/RHSA-2012-0531.html
[libc-alpha] 20120202 [PATCH] vfprintf: validate nargs and positional offsets
http://sourceware.org/ml/libc-alpha/2012-02/msg00023.html
http://sourceware.org/git/?p=glibc.git%3Ba=commitdiff%3Bh=7c1f4834d398163d1ac8101e35e9c36fc3176e6e
http://www.phrack.org/issues.html?issue=67&id=9#article
https://bugzilla.redhat.com/show_bug.cgi?id=794766
CopyrightCopyright (c) 2012 E-Soft Inc. http://www.securityspace.com

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.