PT-2011-1088 · Gnu+2 · Glibc-Common+8

Dan Rosenberg

·

Published

2011-04-10

·

Updated

2016-12-07

·

CVE-2011-1089

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions glibc versions 2.3.4 through 2.13 glibc-utils version 2.3.4 glibc-common version 2.3.4 glibc-devel version 2.3.4 glibc-profile version 2.3.4 glibc-headers version 2.3.4 nptl-devel version 2.3.4
Description The issue concerns multiple vulnerabilities in the glibc package, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited locally. The addmntent function in the GNU C Library does not report an error status for failed attempts to write to the /etc/mtab file, making it easier for local users to trigger corruption of this file.
Recommendations For glibc versions 2.3.4 through 2.13, update to a version later than 2.13 to resolve the issue. For glibc-utils version 2.3.4, update to a version later than 2.3.4 to resolve the issue. For glibc-common version 2.3.4, update to a version later than 2.3.4 to resolve the issue. For glibc-devel version 2.3.4, update to a version later than 2.3.4 to resolve the issue. For glibc-profile version 2.3.4, update to a version later than 2.3.4 to resolve the issue. For glibc-headers version 2.3.4, update to a version later than 2.3.4 to resolve the issue. For nptl-devel version 2.3.4, update to a version later than 2.3.4 to resolve the issue. As a temporary workaround, consider restricting access to the addmntent function until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-05982
BDU:2015-05983
BDU:2015-05984
BDU:2015-05985
BDU:2015-05986
BDU:2015-05987
BDU:2015-06020
BDU:2015-08584
BDU:2015-08585
BDU:2015-08586
BDU:2015-08587
BDU:2015-08588
BDU:2015-08589
BDU:2015-09685
CVE-2011-1089
RHSA-2011:1526
RHSA-2011_1526
RHSA-2012:0125
RHSA-2012:0126
RHSA-2012_0125
RHSA-2012_0126
SUSE-SU-2012_1488-1

Affected Products

Red Hat
Suse
Glibc
Glibc-Common
Glibc-Devel
Glibc-Headers
Glibc-Profile
Glibc-Utils
Nptl-Devel