Lucene search

K
debianDebianDEBIAN:DLA-139-1:5734D
HistoryJan 28, 2015 - 10:25 a.m.

[SECURITY] [DLA 139-1] eglibc security update

2015-01-2810:25:42
lists.debian.org
47

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

8 High

AI Score

Confidence

Low

0.975 High

EPSS

Percentile

100.0%

Package : eglibc
Version : 2.11.3-4+deb6u4
CVE ID : CVE-2015-0235

A vulnerability has been fixed in eglibc, Debian's version of the GNU C
library:

CVE-2015-0235

Qualys discovered that the gethostbyname and gethostbyname2
functions were subject to a buffer overflow if provided with a
crafted IP address argument.  This could be used by an attacker to
execute arbitrary code in processes which called the affected
functions.

The original glibc bug was reported by Peter Klotz.

We recommend that you upgrade your eglibc packages.

The other three CVEs fixed in Debian wheezy via DSA 3142-1 have already been
fixed in squeeze LTS via DLA DLA 97-1.

Attachment:
signature.asc
Description: This is a digitally signed message part.