Otkriven je sigurnosni propust kod paketa glibc u radu na operacijskom sustavu Fedora 17. Napadaču je spomenuti nedostatak omogućavao obilaženje postavljenih sigurnosnih ograničenja.
Paket:
glibc 2.x
Operacijski sustavi:
Fedora 17
Problem:
cjelobrojno prepisivanje
Iskorištavanje:
udaljeno
Posljedica:
zaobilaženje postavljenih ograničenja
Rješenje:
programska zakrpa proizvođača
CVE:
CVE-2012-0864
Izvorni ID preporuke:
FEDORA-2012-2123
Izvor:
Fedora
Problem:
Problem nastaje kao posljedica cjelobrojnog prepisivanja.
Posljedica:
Napadač je ranjivost mogao iskoristiti za obilaženje određenih sigurnosnih ograničenja.
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-2123
2012-02-21 17:40:01
--------------------------------------------------------------------------------
Name : glibc
Product : Fedora 17
Version : 2.15
Release : 23.fc17
URL : http://www.gnu.org/software/glibc/
Summary : The GNU libc libraries
Description :
The glibc package contains standard libraries which are used by
multiple programs on the system. In order to save disk space and
memory, as well as to make upgrading easier, common system code is
kept in one place and shared between programs. This particular package
contains the most important sets of shared libraries: the standard C
library and the standard math library. Without these two libraries, a
Linux system will not function.
--------------------------------------------------------------------------------
Update Information:
Various bugfixes and security enhancements.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #794797 - CVE-2012-0864 glibc: F_S format string protection bypass
via "nargs" integer overflow [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=794797
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update glibc' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Posljednje sigurnosne preporuke