Home > Security > Advisories

Advisories

Mandriva Advisories

Package name glibc
Date December 19th, 2001
Advisory ID MDKSA-2001:095
Affected versions 7.1, 7.2, 8.0, 8.1, CS1.0
Synopsis Updated glibc packages fix buffer overflow vulnerability

Problem Description

Flavio Veloso found an overflowable buffer problem in earlier versions
of the glibc glob(3) implementation. It may be possible to exploit
some programs that pass input to the glibc glob() function in a manner
that can be modified by the user.

Updated Packages

Mandrakelinux 7.1

 516acd7c51fee17ca9bb8a891075075c  7.1/RPMS/glibc-2.1.3-19.1mdk.i586.rpm
5ca14ef88a3d24f3fd9bcba49081ded8  7.1/RPMS/glibc-devel-2.1.3-19.1mdk.i586.rpm
fb24d6b2a254859bc909c36a38d9d139  7.1/RPMS/glibc-profile-2.1.3-19.1mdk.i586.rpm
29e2a828a36cfd258afa3d7e8bcb7f4d  7.1/RPMS/nscd-2.1.3-19.1mdk.i586.rpm
28033029837d789d934a419dfc1131b2  7.1/SRPMS/glibc-2.1.3-19.1mdk.src.rpm

Mandrakelinux 7.2

 e19276709c2a4735ddee4a0951df4e12  7.2/RPMS/glibc-2.1.3-19.2mdk.i586.rpm
92a7e4cee85c42c4ea037df54148a596  7.2/RPMS/glibc-devel-2.1.3-19.2mdk.i586.rpm
3bd6c44c0ab01b82760c4d366f59d781  7.2/RPMS/glibc-profile-2.1.3-19.2mdk.i586.rpm
6972ae990d40b74ea6410a693fec4c7a  7.2/RPMS/nscd-2.1.3-19.2mdk.i586.rpm
3f842988e9aab5ceb3067ec0f9310e09  7.2/SRPMS/glibc-2.1.3-19.2mdk.src.rpm

Mandrakelinux 8.0

 19b2a99c2689b46bdab81adf0fb528be  8.0/RPMS/glibc-2.2.2-6.1mdk.i586.rpm
7f582c2277c07aca00299c17b82d448b  8.0/RPMS/glibc-devel-2.2.2-6.1mdk.i586.rpm
d280e87d1e835ece32b9cacdd2cd9ccd  8.0/RPMS/glibc-profile-2.2.2-6.1mdk.i586.rpm
3dae28acd265003186cda5863ff449c3  8.0/RPMS/ldconfig-2.2.2-6.1mdk.i586.rpm
ece1998a4e8099ebda6f2d03c88bddd8  8.0/RPMS/nscd-2.2.2-6.1mdk.i586.rpm
c324de9da3bcf41124036934d64a2f1c  8.0/SRPMS/glibc-2.2.2-6.1mdk.src.rpm

Mandrakelinux 8.0/PPC

 ad856404147580c30bc044085d044681  ppc/8.0/RPMS/glibc-2.2.2-6.1mdk.ppc.rpm
94f2d80ac1770f789f7ccc154bb5ad58  ppc/8.0/RPMS/glibc-devel-2.2.2-6.1mdk.ppc.rpm
7e6c492400976eefa673e1fd81f2121c  ppc/8.0/RPMS/glibc-profile-2.2.2-6.1mdk.ppc.rpm
ca8663cc2f2ce2a50a6401054a4a182c  ppc/8.0/RPMS/ldconfig-2.2.2-6.1mdk.ppc.rpm
a07ea6eb40ac747ec4c3da16b7905a75  ppc/8.0/RPMS/nscd-2.2.2-6.1mdk.ppc.rpm
c324de9da3bcf41124036934d64a2f1c  ppc/8.0/SRPMS/glibc-2.2.2-6.1mdk.src.rpm

Mandrakelinux 8.1

 2a991be2c3cf7fcf829b653127131719  8.1/RPMS/glibc-2.2.4-9.1mdk.i586.rpm
8742ff16fc01c8bcd89d95564b643e56  8.1/RPMS/glibc-devel-2.2.4-9.1mdk.i586.rpm
1ed7510e9496c6ec2778b2a8dc65206e  8.1/RPMS/glibc-profile-2.2.4-9.1mdk.i586.rpm
ff8053a5491048795b78fbe39ef732ae  8.1/RPMS/ldconfig-2.2.4-9.1mdk.i586.rpm
550a774cdccbcde645cb3ffb8cfa0c12  8.1/RPMS/nscd-2.2.4-9.1mdk.i586.rpm
02d799a94863352278b4fb07b7ff50ff  8.1/SRPMS/glibc-2.2.4-9.1mdk.src.rpm

Mandrakelinux 8.1/IA64

 859380703ef56994ee7170aee273d7ae  ia64/8.1/RPMS/glibc-2.2.4-9.1mdk.ia64.rpm
884fb217b7b4f1982fedb731b7fa9b79  ia64/8.1/RPMS/glibc-devel-2.2.4-9.1mdk.ia64.rpm
8fbfc935cde96781e2ea73167864c571  ia64/8.1/RPMS/glibc-profile-2.2.4-9.1mdk.ia64.rpm
63a40508fcbab4cce75436994a356184  ia64/8.1/RPMS/ldconfig-2.2.4-9.1mdk.ia64.rpm
174dee8685f5549aabb40d650ed32079  ia64/8.1/RPMS/nscd-2.2.4-9.1mdk.ia64.rpm
02d799a94863352278b4fb07b7ff50ff  ia64/8.1/SRPMS/glibc-2.2.4-9.1mdk.src.rpm

Corporate Server 1.0.1

 516acd7c51fee17ca9bb8a891075075c  1.0.1/RPMS/glibc-2.1.3-19.1mdk.i586.rpm
5ca14ef88a3d24f3fd9bcba49081ded8  1.0.1/RPMS/glibc-devel-2.1.3-19.1mdk.i586.rpm
fb24d6b2a254859bc909c36a38d9d139  1.0.1/RPMS/glibc-profile-2.1.3-19.1mdk.i586.rpm
29e2a828a36cfd258afa3d7e8bcb7f4d  1.0.1/RPMS/nscd-2.1.3-19.1mdk.i586.rpm
28033029837d789d934a419dfc1131b2  1.0.1/SRPMS/glibc-2.1.3-19.1mdk.src.rpm

References

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2001-0886

Upgrade

To upgrade automatically, use MandrivaUpdate.


Verification

Please verify the update prior to upgrading to ensure the integrity of the downloaded package. You can do this with the command :

                rpm --checksig package.rpm
                

You can get the GPG public key of the Mandriva Security Team to verify the GPG signature of each RPM.

If you use MandrivaUpdate, the verification of md5 checksum and GPG signature is performed automatically for you.