PT-2011-1088 · Gnu+2 · Glibc-Common+8
Dan Rosenberg
·
Publicado
2011-04-10
·
Atualizado
2016-12-07
·
CVE-2011-1089
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
glibc versions 2.3.4 through 2.13
glibc-utils version 2.3.4
glibc-common version 2.3.4
glibc-devel version 2.3.4
glibc-profile version 2.3.4
glibc-headers version 2.3.4
nptl-devel version 2.3.4
Description
The issue concerns multiple vulnerabilities in the glibc package, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited locally. The
addmntent function in the GNU C Library does not report an error status for failed attempts to write to the /etc/mtab file, making it easier for local users to trigger corruption of this file.Recommendations
For glibc versions 2.3.4 through 2.13, update to a version later than 2.13 to resolve the issue.
For glibc-utils version 2.3.4, update to a version later than 2.3.4 to resolve the issue.
For glibc-common version 2.3.4, update to a version later than 2.3.4 to resolve the issue.
For glibc-devel version 2.3.4, update to a version later than 2.3.4 to resolve the issue.
For glibc-profile version 2.3.4, update to a version later than 2.3.4 to resolve the issue.
For glibc-headers version 2.3.4, update to a version later than 2.3.4 to resolve the issue.
For nptl-devel version 2.3.4, update to a version later than 2.3.4 to resolve the issue.
As a temporary workaround, consider restricting access to the
addmntent function until a patch is available.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Red Hat
Suse
Glibc
Glibc-Common
Glibc-Devel
Glibc-Headers
Glibc-Profile
Glibc-Utils
Nptl-Devel