http://www.mandriva.com/en/
______________________________
Package : glibc
Date : September 5, 2014
Affected: Business Server 1.0
______________________________
Problem Description:
Multiple vulnerabilities has been found and corrected in glibc:
When converting IBM930 code with iconv(), if IBM930 code which includes
invalid multibyte character 0xffff is specified, then iconv() segfaults
(CVE-2012-6656).
Off-by-one error in the __gconv_translit_find function in gconv_trans.c
in GNU C Library (aka glibc) allows context-dependent attackers to
cause a denial of service (crash) or execute arbitrary code via vectors
related to the CHARSET environment variable and gconv transliteration
modules (CVE-2014-5119).
Crashes were reported in the IBM code page decoding functions (IBM933,
IBM935, IBM937, IBM939, IBM1364) (CVE-2014-6040).
The updated packages have been patched to correct these issues.
______________________________
References:
http://cve.mitre.org/cgi-bin/
http://cve.mitre.org/cgi-bin/
http://cve.mitre.org/cgi-bin/
https://rhn.redhat.com/errata/
https://sourceware.org/
https://sourceware.org/
http://seclists.org/oss-sec/
https://bugzilla.redhat.com/
______________________________
_____________
Updated Packages:
Mandriva Business Server 1/X86_64:
85b7b4e252324a0590706605fe3a9d
63cd91495f99e794eb0281b7c9ee2e
21d0709e256566ee526e9fbb0197b6
8ea25400b2d708f2d7da22df4a5a62
dfc7aae076e0a66b236968ee0af8e7
ebf493606c89def3d6bfca87749bbf
6ad78068de0280f4584d5e8b70890d
c796168f27f0236d7cd9123aba6e5e
044ada512f6397981550cb3342a481
5fc48f30a7f358c201b72be63a7a67
______________________________
To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.
All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:
gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
http://www.mandriva.com/en/
If you want to report vulnerabilities, please contact
security_(at)_mandriva.com
Komentarų nėra:
Rašyti komentarą