Skip to navigation

Security Advisory glibc security update

Advisory: RHSA-2003:022-09
Type: Security Advisory
Severity: Moderate
Issued on: 2003-02-04
Last updated on: 2003-02-04
Affected Products: Red Hat Enterprise Linux AS (v. 2.1)
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor
CVEs (cve.mitre.org): CVE-2002-1146

Details

Updated glibc packages are available to fix a buffer overflow in the
resolver.

The GNU C library package, glibc, contains standard libraries used by
multiple programs on the system.

A read buffer overflow vulnerability exists in the glibc resolver code in
versions of glibc up to and including 2.2.5. The vulnerability is triggered
by DNS packets larger than 1024 bytes and can cause applications to crash.

In addition to this, several non-security related bugs have been fixed,
the majority for the Itanium (IA64) platform.

All Red Hat Linux Advanced Server users are advised to upgrade to these
errata packages which contain a patch to correct this vulnerability.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

Please note that this update is available via Red Hat Network. To use Red
Hat Network, launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Updated packages

Red Hat Enterprise Linux AS (v. 2.1)

SRPMS:
glibc-2.2.4-31.7.src.rpm
File outdated by:  RHEA-2006:0279
    MD5: 552d328584c6c06455087b6d366c6493
 
IA-32:
glibc-2.2.4-31.7.i386.rpm
File outdated by:  RHEA-2006:0279
    MD5: 2c877c134c0da7b31b55f1fad8464a6d
glibc-2.2.4-31.7.i686.rpm
File outdated by:  RHEA-2006:0279
    MD5: 848f41d568de4da3032568953ae46d83
glibc-common-2.2.4-31.7.i386.rpm
File outdated by:  RHEA-2006:0279
    MD5: d737b7ac2b5028dedb8c843f6097b4cc
glibc-devel-2.2.4-31.7.i386.rpm
File outdated by:  RHEA-2006:0279
    MD5: 29e817a6b60aeec4d2b9bc55f8462579
glibc-profile-2.2.4-31.7.i386.rpm
File outdated by:  RHEA-2006:0279
    MD5: 46ac52f96ff98600b83f96cfbf16e2a1
nscd-2.2.4-31.7.i386.rpm
File outdated by:  RHEA-2006:0279
    MD5: 5ce824c8e35c028229d493f9cf3b1ca9
 
IA-64:
glibc-2.2.4-31.7.ia64.rpm
File outdated by:  RHEA-2006:0279
    MD5: 6cefb73a326789d6f001377624a02299
glibc-common-2.2.4-31.7.ia64.rpm
File outdated by:  RHEA-2006:0279
    MD5: 3d26728ce0dc0bd1eb6b5b3fba6ce566
glibc-devel-2.2.4-31.7.ia64.rpm
File outdated by:  RHEA-2006:0279
    MD5: 694cb6fa71ad1f83a7e98d9153764eeb
glibc-profile-2.2.4-31.7.ia64.rpm
File outdated by:  RHEA-2006:0279
    MD5: b80396345feb81e4beca245bceefbe3a
nscd-2.2.4-31.7.ia64.rpm
File outdated by:  RHEA-2006:0279
    MD5: 9139c4504097104daf47c9c39b7e790f
 
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor

SRPMS:
glibc-2.2.4-31.7.src.rpm
File outdated by:  RHEA-2006:0279
    MD5: 552d328584c6c06455087b6d366c6493
 
IA-64:
glibc-2.2.4-31.7.ia64.rpm
File outdated by:  RHEA-2006:0279
    MD5: 6cefb73a326789d6f001377624a02299
glibc-common-2.2.4-31.7.ia64.rpm
File outdated by:  RHEA-2006:0279
    MD5: 3d26728ce0dc0bd1eb6b5b3fba6ce566
glibc-devel-2.2.4-31.7.ia64.rpm
File outdated by:  RHEA-2006:0279
    MD5: 694cb6fa71ad1f83a7e98d9153764eeb
glibc-profile-2.2.4-31.7.ia64.rpm
File outdated by:  RHEA-2006:0279
    MD5: b80396345feb81e4beca245bceefbe3a
nscd-2.2.4-31.7.ia64.rpm
File outdated by:  RHEA-2006:0279
    MD5: 9139c4504097104daf47c9c39b7e790f
 

Bugs fixed (see bugzilla for more information)

63934 - A Process may hugup when multithread process is completed.
65816 - mcount profiling has apparent problem on IA64
66548 - Max threads limit on RedHat Linux
70463 - vfprintf does not properly handle wide strings with precision of 0
73694 - forkexec and resulting stack limit differences (pthread vs. no pthread)
74742 - SIGSTKSZ & MINSIGSTKSZ are *way* off
76245 - mcount profiling has apparent problem on IA64 (bugzilla #65816)
76591 - glibc bugfix for statically linked app failure
76952 - strncpy(d,s,n) fails when s paged out and n > 24


References


Keywords

DNS, flaw:buf, glibc, strncpy


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/