LWN.net Logo

glibc: multiple vulnerabilities

Package(s):eglibc, glibc CVE #(s):CVE-2011-1658 CVE-2011-2702
Created:March 12, 2012 Updated:March 14, 2012
Description: From the Ubuntu advisory:

It was discovered that the GNU C library loader expanded the $ORIGIN dynamic string token when RPATH is composed entirely of this token. This could allow an attacker to gain privilege via a setuid program that had this RPATH value. (CVE-2011-1658)

It was discovered that the GNU C library implementation of memcpy optimized for Supplemental Streaming SIMD Extensions 3 (SSSE3) contained a possible integer overflow. An attacker could use this to cause a denial of service or possibly execute arbitrary code. This issue only affected Ubuntu 10.04 LTS. (CVE-2011-2702)

Alerts:
Ubuntu USN-1396-1 2012-03-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds