Jeff Layton

Pesquisador deRed Hat
#8442de 53,638
32.5CVSS total
Vulnerabilidades · 5
Média
3
Alta
2
PT-2008-6879
7.2
1970-01-01
Gnu · Libc6 · CVE-2010-0296
**Name of the Vulnerable Software and Affected Versions** glibc versions prior to 2.11.2 libc6 versions prior to 2.11.2 libc6-dev versions prior to 2.11.2 glibc-2.3.4 glibc-profile-2.3.4 glibc-headers-2.3.4 glibc-utils-2.3.4 glibc-common-2.3.4 glibc-devel-2.3.4 glibc-debuginfo glibc-profile-64bit glibc-locale-64bit glibc-dceext glibc-dceext-32bit libc6-i386 libc6-sparcv9b libc6-mipsn32 libc6-xen libc6-amd64 libc6-sparc64 libc6-ppc64 libc6-mips64 libc6-s390x libc6-dev-sparc64 libc6-dev-mips64 libc6-dev-mipsn32 libc6-dev-ppc64 libc6-dev-s390x libc6-dev-amd64 libc6.1 libc6.1-dev libc6.1-pic libc6.1-udeb libc6.1-alphaev67 libc6-dbg libc6-prof libc6-pic libnss-dns-udeb libnss-files-udeb locales locales-all nptl-devel-2.3.4 nscd **Description** The issue is related to multiple vulnerabilities in the glibc and libc6 packages, which can lead to a disruption of confidentiality, integrity, and availability of protected information. The vulnerabilities can be exploited remotely or locally, depending on the specific package and version. The `encode name` macro in `misc/mntent r.c` is specifically mentioned as being vulnerable to newline characters in mountpoint names, allowing local users to cause a denial of service or possibly modify mount options and gain privileges. **Recommendations** For glibc versions prior to 2.11.2, update to version 2.11.2 or later. For libc6 versions prior to 2.11.2, update to version 2.11.2 or later. For libc6-dev versions prior to 2.11.2, update to version 2.11.2 or later. For glibc-2.3.4, glibc-profile-2.3.4, glibc-headers-2.3.4, glibc-utils-2.3.4, glibc-common-2.3.4, and glibc-devel-2.3.4, update to a version later than 2.3.4. For other affected packages, update to the latest available version. As a temporary workaround, consider disabling the `encode name` macro until a patch is available. Restrict access to the vulnerable packages to minimize the risk of exploitation. Avoid using the vulnerable functions and parameters until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.