Skip to navigation

Security Advisory Updated glibc packages fix vulnerabilities in resolver

Advisory: RHSA-2002:197-09
Type: Security Advisory
Severity: N/A
Issued on: 2002-09-10
Last updated on: 2002-11-06
Affected Products: Red Hat Linux 6.2
Red Hat Linux 7.0
Red Hat Linux 7.1
Red Hat Linux 7.2
Red Hat Linux 7.3
CVEs (cve.mitre.org): CVE-2002-1146

Details

Updated glibc packages are available to fix a buffer overflow in the
resolver.

The GNU C library package, glibc, contains standard libraries used by
multiple programs on the system.

A read buffer overflow vulnerability exists in the glibc resolver code in
versions of glibc up to and including 2.2.5. The vulnerability is
triggered by DNS packets larger than 1024 bytes and can cause applications
to crash.

All Red Hat Linux users are advised to upgrade to these errata packages
which contain a patch to correct this vulnerability.

This errata has been updated to work with programs querying DNS from
extremely small stack sizes, such as MySQL.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those
RPMs which are currently installed will be updated. Those RPMs which are
not installed but included in the list will not be updated. Note that you
can also use wildcards (*.rpm) if your current directory *only* contains the
desired RPMs.

Please note that this update is also available via Red Hat Network. Many
people find this an easier way to apply updates. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Updated packages

Red Hat Linux 6.2

SRPMS:
glibc-2.1.3-28.src.rpm
File outdated by:  RHSA-2003:089
    MD5: 42a492e324a0cc4f20b69d90e17a72be
 
Alpha:
ftp://updates.redhat.com/rhn/repository/NULL/glibc/2.1.3-28/alpha/glibc-2.1.3-28.alpha.rpm
Missing file
    MD5: e0a2f8aad3c4a1a98f6f298bbfff3a23
ftp://updates.redhat.com/rhn/repository/NULL/glibc-devel/2.1.3-28/alpha/glibc-devel-2.1.3-28.alpha.rpm
Missing file
    MD5: 0b85f0e0b3138ecdf01cd0bcbf18f15d
ftp://updates.redhat.com/rhn/repository/NULL/glibc-profile/2.1.3-28/alpha/glibc-profile-2.1.3-28.alpha.rpm
Missing file
    MD5: e9c22cf335364a26b397769540abbbaf
ftp://updates.redhat.com/rhn/repository/NULL/nscd/2.1.3-28/alpha/nscd-2.1.3-28.alpha.rpm
Missing file
    MD5: c03a7ec95d367074bb511407323b0225
 
IA-32:
glibc-2.1.3-28.i386.rpm
File outdated by:  RHSA-2003:089
    MD5: 60dd8a722a6356a303da8e9f7b9d69ed
glibc-devel-2.1.3-28.i386.rpm
File outdated by:  RHSA-2003:089
    MD5: 6c18ceb25365761f1b9c8f0a0080e696
glibc-profile-2.1.3-28.i386.rpm
File outdated by:  RHSA-2003:089
    MD5: ba1a8c76d4f7caa53a4a7dc62e840ad2
nscd-2.1.3-28.i386.rpm
File outdated by:  RHSA-2003:089
    MD5: 7e322c41b89b4a769393c5f11024c959
 
Sparc:
ftp://updates.redhat.com/rhn/repository/NULL/glibc/2.1.3-28/sparc/glibc-2.1.3-28.sparc.rpm
Missing file
    MD5: 7418ba95b213cd7fcf19fc09cf76605f
ftp://updates.redhat.com/rhn/repository/NULL/glibc/2.1.3-28/sparcv9/glibc-2.1.3-28.sparcv9.rpm
Missing file
    MD5: efc4db25f9fe9b5fa7e9f96c85100ac0
ftp://updates.redhat.com/rhn/repository/NULL/glibc-devel/2.1.3-28/sparc/glibc-devel-2.1.3-28.sparc.rpm
Missing file
    MD5: 01b589a9b3a4e09ea988ece90a2296c6
ftp://updates.redhat.com/rhn/repository/NULL/glibc-profile/2.1.3-28/sparc/glibc-profile-2.1.3-28.sparc.rpm
Missing file
    MD5: 2a0c90b3b5722da24a618e1ce2bfe2df
ftp://updates.redhat.com/rhn/repository/NULL/nscd/2.1.3-28/sparc/nscd-2.1.3-28.sparc.rpm
Missing file
    MD5: 8b8a85fa1a19766491740a221d6e1bc5
 
Red Hat Linux 7.0

SRPMS:
glibc-2.2.4-18.7.0.8.src.rpm
File outdated by:  RHSA-2003:089
    MD5: aff33cd665fae333c81ea6d563590f44
 
Alpha:
ftp://updates.redhat.com/rhn/repository/NULL/glibc/2.2.4-18.7.0.8/alpha/glibc-2.2.4-18.7.0.8.alpha.rpm
Missing file
    MD5: 78ca07577d9d808c26d78ef14b0a55aa
ftp://updates.redhat.com/rhn/repository/NULL/glibc/2.2.4-18.7.0.8/alphaev6/glibc-2.2.4-18.7.0.8.alphaev6.rpm
Missing file
    MD5: 94f6353c050fa59f290923abc646b3d2
ftp://updates.redhat.com/rhn/repository/NULL/glibc-common/2.2.4-18.7.0.8/alpha/glibc-common-2.2.4-18.7.0.8.alpha.rpm
Missing file
    MD5: 3bba5726623b9c032fe1428d9d6a7629
ftp://updates.redhat.com/rhn/repository/NULL/glibc-devel/2.2.4-18.7.0.8/alpha/glibc-devel-2.2.4-18.7.0.8.alpha.rpm
Missing file
    MD5: 61e72d9da7224e9dd524822e91c87277
ftp://updates.redhat.com/rhn/repository/NULL/glibc-profile/2.2.4-18.7.0.8/alpha/glibc-profile-2.2.4-18.7.0.8.alpha.rpm
Missing file
    MD5: 4144c1872eb0972a40871255ea89c635
ftp://updates.redhat.com/rhn/repository/NULL/nscd/2.2.4-18.7.0.8/alpha/nscd-2.2.4-18.7.0.8.alpha.rpm
Missing file
    MD5: e14c1bc6749a3c9bdef02e17372d41ad
 
IA-32:
glibc-2.2.4-18.7.0.8.i386.rpm
File outdated by:  RHSA-2003:089
    MD5: ea58433070049d671f3b5f4e203d9338
glibc-2.2.4-18.7.0.8.i686.rpm
File outdated by:  RHSA-2003:089
    MD5: d7659100582f611de380e8c447d511cb
glibc-common-2.2.4-18.7.0.8.i386.rpm
File outdated by:  RHSA-2003:089
    MD5: 4a58431cdb351e4e3deec2114f67b028
glibc-devel-2.2.4-18.7.0.8.i386.rpm
File outdated by:  RHSA-2003:089
    MD5: 3e349a1f71ef0c48000ea5583631dc20
glibc-profile-2.2.4-18.7.0.8.i386.rpm
File outdated by:  RHSA-2003:089
    MD5: 001f8fa9f9c8bca35d0f0af49a48569d
nscd-2.2.4-18.7.0.8.i386.rpm
File outdated by:  RHSA-2003:089
    MD5: 0fe541f7666962bc2026277d15f19686
 
Red Hat Linux 7.1

SRPMS:
glibc-2.2.4-31.src.rpm
File outdated by:  RHSA-2003:325
    MD5: 93f5da8fdaea659c7052cd981034f000
 
Alpha:
ftp://updates.redhat.com/rhn/repository/NULL/glibc/2.2.4-31/alpha/glibc-2.2.4-31.alpha.rpm
Missing file
    MD5: 7e914fcb9302c7e0cc0586e2ef9d96f3
ftp://updates.redhat.com/rhn/repository/NULL/glibc/2.2.4-31/alphaev6/glibc-2.2.4-31.alphaev6.rpm
Missing file
    MD5: 4d1edebe2f7428b37b19b3ef94d39aca
ftp://updates.redhat.com/rhn/repository/NULL/glibc-common/2.2.4-31/alpha/glibc-common-2.2.4-31.alpha.rpm
Missing file
    MD5: c8c0cd28dd1dbfb96f3e720116e1f9c5
ftp://updates.redhat.com/rhn/repository/NULL/glibc-devel/2.2.4-31/alpha/glibc-devel-2.2.4-31.alpha.rpm
Missing file
    MD5: 1f5c23f0951e575f9085a82686feb741
ftp://updates.redhat.com/rhn/repository/NULL/glibc-profile/2.2.4-31/alpha/glibc-profile-2.2.4-31.alpha.rpm
Missing file
    MD5: 8562e79e28ae22409ea6df96b47aa8c7
ftp://updates.redhat.com/rhn/repository/NULL/nscd/2.2.4-31/alpha/nscd-2.2.4-31.alpha.rpm
Missing file
    MD5: a49cca3797b8f418169a96c8ecf5ff97
 
IA-32:
glibc-2.2.4-31.i386.rpm
File outdated by:  RHSA-2003:325
    MD5: ed5a12d2eba916b92a58d8538216d2fe
glibc-2.2.4-31.i686.rpm
File outdated by:  RHSA-2003:325
    MD5: 0ec3f0c56dca284b671ef5662e04cd35
glibc-common-2.2.4-31.i386.rpm
File outdated by:  RHSA-2003:325
    MD5: 7e45b087c1772f1dd45fc42b20b62309
glibc-devel-2.2.4-31.i386.rpm
File outdated by:  RHSA-2003:325
    MD5: 25b4435bc74e97e7a64c48c3e352c562
glibc-profile-2.2.4-31.i386.rpm
File outdated by:  RHSA-2003:325
    MD5: acddc14c428cedbba3b91b5e478b762e
nscd-2.2.4-31.i386.rpm
File outdated by:  RHSA-2003:325
    MD5: e6be96e0b11915217dcaedcf4db6e9ed
 
IA-64:
ftp://updates.redhat.com/rhn/repository/NULL/glibc/2.2.4-31/ia64/glibc-2.2.4-31.ia64.rpm
Missing file
    MD5: a83b3035a19f0ce800894ccf0dcceb24
ftp://updates.redhat.com/rhn/repository/NULL/glibc-common/2.2.4-31/ia64/glibc-common-2.2.4-31.ia64.rpm
Missing file
    MD5: 7f1bda1e43db315c9298ba59ba676940
ftp://updates.redhat.com/rhn/repository/NULL/glibc-devel/2.2.4-31/ia64/glibc-devel-2.2.4-31.ia64.rpm
Missing file
    MD5: be62314ba425a28cbe82c032ed71376b
ftp://updates.redhat.com/rhn/repository/NULL/glibc-profile/2.2.4-31/ia64/glibc-profile-2.2.4-31.ia64.rpm
Missing file
    MD5: d031b71272bf6ba6376ef35fa85dfbc5
ftp://updates.redhat.com/rhn/repository/NULL/nscd/2.2.4-31/ia64/nscd-2.2.4-31.ia64.rpm
Missing file
    MD5: db1adfb98f185007ca3af87334e86ce1
 
Red Hat Linux 7.2

SRPMS:
glibc-2.2.4-31.src.rpm
File outdated by:  RHSA-2003:325
    MD5: 93f5da8fdaea659c7052cd981034f000
 
IA-32:
glibc-2.2.4-31.i386.rpm
File outdated by:  RHSA-2003:325
    MD5: ed5a12d2eba916b92a58d8538216d2fe
glibc-2.2.4-31.i686.rpm
File outdated by:  RHSA-2003:325
    MD5: 0ec3f0c56dca284b671ef5662e04cd35
glibc-common-2.2.4-31.i386.rpm
File outdated by:  RHSA-2003:325
    MD5: 7e45b087c1772f1dd45fc42b20b62309
glibc-devel-2.2.4-31.i386.rpm
File outdated by:  RHSA-2003:325
    MD5: 25b4435bc74e97e7a64c48c3e352c562
glibc-profile-2.2.4-31.i386.rpm
File outdated by:  RHSA-2003:325
    MD5: acddc14c428cedbba3b91b5e478b762e
nscd-2.2.4-31.i386.rpm
File outdated by:  RHSA-2003:325
    MD5: e6be96e0b11915217dcaedcf4db6e9ed
 
IA-64:
glibc-2.2.4-31.ia64.rpm
File outdated by:  RHSA-2003:325
    MD5: a83b3035a19f0ce800894ccf0dcceb24
glibc-common-2.2.4-31.ia64.rpm
File outdated by:  RHSA-2003:325
    MD5: 7f1bda1e43db315c9298ba59ba676940
glibc-devel-2.2.4-31.ia64.rpm
File outdated by:  RHSA-2003:325
    MD5: be62314ba425a28cbe82c032ed71376b
glibc-profile-2.2.4-31.ia64.rpm
File outdated by:  RHSA-2003:325
    MD5: d031b71272bf6ba6376ef35fa85dfbc5
nscd-2.2.4-31.ia64.rpm
File outdated by:  RHSA-2003:325
    MD5: db1adfb98f185007ca3af87334e86ce1
 
Red Hat Linux 7.3

SRPMS:
glibc-2.2.5-42.src.rpm
File outdated by:  RHSA-2003:325
    MD5: 6265863572fb3e7a1b486eca6596592f
 
IA-32:
glibc-2.2.5-42.i386.rpm
File outdated by:  RHSA-2003:325
    MD5: 4750678e10a0aefab9430fe2a5712fdc
glibc-2.2.5-42.i686.rpm
File outdated by:  RHSA-2003:325
    MD5: af653b45403a81d59fca747f6af03b1f
glibc-common-2.2.5-42.i386.rpm
File outdated by:  RHSA-2003:325
    MD5: 8bd67044b7e03f7f289fdf79bc7319f3
glibc-debug-2.2.5-42.i386.rpm
File outdated by:  RHSA-2003:325
    MD5: 5a6657acde4fa1898d0bb99dc3ec8490
glibc-debug-2.2.5-42.i686.rpm
File outdated by:  RHSA-2003:325
    MD5: 335b38bdca65cf56dd0fd80fbad84510
glibc-debug-static-2.2.5-42.i386.rpm
File outdated by:  RHSA-2003:325
    MD5: 85d826d4a5bcb1b32b37dddcbd41aa91
glibc-devel-2.2.5-42.i386.rpm
File outdated by:  RHSA-2003:325
    MD5: a7aacd713dac9b63bcb9f2ff3cac5661
glibc-profile-2.2.5-42.i386.rpm
File outdated by:  RHSA-2003:325
    MD5: ab5f10edc78d202d94c11b3d5fcf6503
glibc-utils-2.2.5-42.i386.rpm
File outdated by:  RHSA-2003:325
    MD5: 2c86e5649ce5497316a524a47297e3b7
nscd-2.2.5-42.i386.rpm
File outdated by:  RHSA-2003:325
    MD5: a50db12732df7218df84db14d56731a3
 

Bugs fixed (see bugzilla for more information)

73694 - forkexec and resulting stack limit differences (pthread vs. no pthread)
75128 - MySQL hangs/crashes after glibc upgrade


References


Keywords

DNS, glibc, resolv


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/