PT-2012-1065 · Gnu+2 · Glibc-Utils+8

Publicado

2012-01-24

·

Atualizado

2013-05-03

·

CVE-2011-4609

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions glibc versions 2.3.4 glibc-common versions 2.3.4 glibc-devel versions 2.3.4 glibc-headers versions 2.3.4 glibc-profile versions 2.3.4 glibc-utils versions 2.3.4 nptl-devel versions 2.3.4
Description The issue affects the glibc package in Red Hat Enterprise Linux and CentOS operating systems, allowing for potential disruption of confidentiality, integrity, and availability of protected information. Exploitation can be carried out locally. The svc run function in the RPC implementation is also vulnerable, enabling remote attackers to cause a denial of service via a large number of RPC connections.
Recommendations For glibc versions 2.3.4, consider updating to a version prior to 2.15 to mitigate the risk. For glibc-common versions 2.3.4, consider updating to a version prior to 2.15 to mitigate the risk. For glibc-devel versions 2.3.4, consider updating to a version prior to 2.15 to mitigate the risk. For glibc-headers versions 2.3.4, consider updating to a version prior to 2.15 to mitigate the risk. For glibc-profile versions 2.3.4, consider updating to a version prior to 2.15 to mitigate the risk. For glibc-utils versions 2.3.4, consider updating to a version prior to 2.15 to mitigate the risk. For nptl-devel versions 2.3.4, consider updating to a version prior to 2.15 to mitigate the risk. As a temporary workaround, consider disabling the svc run function until a patch is available.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-05982
BDU:2015-05983
BDU:2015-05984
BDU:2015-05985
BDU:2015-05986
BDU:2015-05987
BDU:2015-06020
BDU:2015-08584
BDU:2015-08585
BDU:2015-08586
BDU:2015-08587
BDU:2015-08588
BDU:2015-08589
CESA-2012_0058
CVE-2011-4609
RHSA-2012:0058
RHSA-2012:0125
RHSA-2012:0126
RHSA-2012_0058
RHSA-2012_0125
RHSA-2012_0126

Produtos afetados

Centos
Red Hat
Glibc
Glibc-Common
Glibc-Devel
Glibc-Headers
Glibc-Profile
Glibc-Utils
Nptl-Devel