glibc security update
| Advisory: | RHSA-2003:022-09 |
|---|---|
| Type: | Security Advisory |
| Severity: | Moderate |
| Issued on: | 2003-02-04 |
| Last updated on: | 2003-02-04 |
| Affected Products: | Red Hat Enterprise Linux AS (v. 2.1) Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor |
| CVEs (cve.mitre.org): |
CVE-2002-1146 |
Details
Updated glibc packages are available to fix a buffer overflow in the
resolver.
The GNU C library package, glibc, contains standard libraries used by
multiple programs on the system.
A read buffer overflow vulnerability exists in the glibc resolver code in
versions of glibc up to and including 2.2.5. The vulnerability is triggered
by DNS packets larger than 1024 bytes and can cause applications to crash.
In addition to this, several non-security related bugs have been fixed,
the majority for the Itanium (IA64) platform.
All Red Hat Linux Advanced Server users are advised to upgrade to these
errata packages which contain a patch to correct this vulnerability.
Solution
relevant to your system have been applied.
Please note that this update is available via Red Hat Network. To use Red
Hat Network, launch the Red Hat Update Agent with the following command:
up2date
This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.
Updated packages
| Red Hat Enterprise Linux AS (v. 2.1) | |
| SRPMS: | |
| glibc-2.2.4-31.7.src.rpm File outdated by: RHEA-2006:0279 |
MD5: 552d328584c6c06455087b6d366c6493 |
| IA-32: | |
| glibc-2.2.4-31.7.i386.rpm File outdated by: RHEA-2006:0279 |
MD5: 2c877c134c0da7b31b55f1fad8464a6d |
| glibc-2.2.4-31.7.i686.rpm File outdated by: RHEA-2006:0279 |
MD5: 848f41d568de4da3032568953ae46d83 |
| glibc-common-2.2.4-31.7.i386.rpm File outdated by: RHEA-2006:0279 |
MD5: d737b7ac2b5028dedb8c843f6097b4cc |
| glibc-devel-2.2.4-31.7.i386.rpm File outdated by: RHEA-2006:0279 |
MD5: 29e817a6b60aeec4d2b9bc55f8462579 |
| glibc-profile-2.2.4-31.7.i386.rpm File outdated by: RHEA-2006:0279 |
MD5: 46ac52f96ff98600b83f96cfbf16e2a1 |
| nscd-2.2.4-31.7.i386.rpm File outdated by: RHEA-2006:0279 |
MD5: 5ce824c8e35c028229d493f9cf3b1ca9 |
| IA-64: | |
| glibc-2.2.4-31.7.ia64.rpm File outdated by: RHEA-2006:0279 |
MD5: 6cefb73a326789d6f001377624a02299 |
| glibc-common-2.2.4-31.7.ia64.rpm File outdated by: RHEA-2006:0279 |
MD5: 3d26728ce0dc0bd1eb6b5b3fba6ce566 |
| glibc-devel-2.2.4-31.7.ia64.rpm File outdated by: RHEA-2006:0279 |
MD5: 694cb6fa71ad1f83a7e98d9153764eeb |
| glibc-profile-2.2.4-31.7.ia64.rpm File outdated by: RHEA-2006:0279 |
MD5: b80396345feb81e4beca245bceefbe3a |
| nscd-2.2.4-31.7.ia64.rpm File outdated by: RHEA-2006:0279 |
MD5: 9139c4504097104daf47c9c39b7e790f |
| Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor | |
| SRPMS: | |
| glibc-2.2.4-31.7.src.rpm File outdated by: RHEA-2006:0279 |
MD5: 552d328584c6c06455087b6d366c6493 |
| IA-64: | |
| glibc-2.2.4-31.7.ia64.rpm File outdated by: RHEA-2006:0279 |
MD5: 6cefb73a326789d6f001377624a02299 |
| glibc-common-2.2.4-31.7.ia64.rpm File outdated by: RHEA-2006:0279 |
MD5: 3d26728ce0dc0bd1eb6b5b3fba6ce566 |
| glibc-devel-2.2.4-31.7.ia64.rpm File outdated by: RHEA-2006:0279 |
MD5: 694cb6fa71ad1f83a7e98d9153764eeb |
| glibc-profile-2.2.4-31.7.ia64.rpm File outdated by: RHEA-2006:0279 |
MD5: b80396345feb81e4beca245bceefbe3a |
| nscd-2.2.4-31.7.ia64.rpm File outdated by: RHEA-2006:0279 |
MD5: 9139c4504097104daf47c9c39b7e790f |
Bugs fixed (see bugzilla for more information)
63934 - A Process may hugup when multithread process is completed.
65816 - mcount profiling has apparent problem on IA64
66548 - Max threads limit on RedHat Linux
70463 - vfprintf does not properly handle wide strings with precision of 0
73694 - forkexec and resulting stack limit differences (pthread vs. no pthread)
74742 - SIGSTKSZ & MINSIGSTKSZ are *way* off
76245 - mcount profiling has apparent problem on IA64 (bugzilla #65816)
76591 - glibc bugfix for statically linked app failure
76952 - strncpy(d,s,n) fails when s paged out and n > 24
References
Keywords
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package
The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/