what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Mandriva Linux Security Advisory 2014-175

Mandriva Linux Security Advisory 2014-175
Posted Sep 8, 2014
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2014-175 - When converting IBM930 code with iconv(), if IBM930 code which includes invalid multibyte character 0xffff is specified, then iconv() segfaults. Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library allows context-dependent attackers to cause a denial of service or execute arbitrary code via vectors related to the CHARSET environment variable and gconv transliteration modules. Crashes were reported in the IBM code page decoding functions (IBM933, IBM935, IBM937, IBM939, IBM1364). The updated packages have been patched to correct these issues.

tags | advisory, denial of service, arbitrary
systems | linux, mandriva
advisories | CVE-2012-6656, CVE-2014-5119, CVE-2014-6040
SHA-256 | f3306f4d40c605cd5282642a6815dd2da169dca7f32fb2e4796c7ec5dcb10aa7

Mandriva Linux Security Advisory 2014-175

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDVSA-2014:175
http://www.mandriva.com/en/support/security/
_______________________________________________________________________

Package : glibc
Date : September 5, 2014
Affected: Business Server 1.0
_______________________________________________________________________

Problem Description:

Multiple vulnerabilities has been found and corrected in glibc:

When converting IBM930 code with iconv(), if IBM930 code which includes
invalid multibyte character 0xffff is specified, then iconv() segfaults
(CVE-2012-6656).

Off-by-one error in the __gconv_translit_find function in gconv_trans.c
in GNU C Library (aka glibc) allows context-dependent attackers to
cause a denial of service (crash) or execute arbitrary code via vectors
related to the CHARSET environment variable and gconv transliteration
modules (CVE-2014-5119).

Crashes were reported in the IBM code page decoding functions (IBM933,
IBM935, IBM937, IBM939, IBM1364) (CVE-2014-6040).

The updated packages have been patched to correct these issues.
_______________________________________________________________________

References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6656
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5119
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6040
https://rhn.redhat.com/errata/RHSA-2014-1110.html
https://sourceware.org/bugzilla/show_bug.cgi?id=14134
https://sourceware.org/bugzilla/show_bug.cgi?id=17325
http://seclists.org/oss-sec/2014/q3/485
https://bugzilla.redhat.com/show_bug.cgi?id=1135841
_______________________________________________________________________

Updated Packages:

Mandriva Business Server 1/X86_64:
85b7b4e252324a0590706605fe3a9d96 mbs1/x86_64/glibc-2.14.1-12.9.mbs1.x86_64.rpm
63cd91495f99e794eb0281b7c9ee2e32 mbs1/x86_64/glibc-devel-2.14.1-12.9.mbs1.x86_64.rpm
21d0709e256566ee526e9fbb0197b637 mbs1/x86_64/glibc-doc-2.14.1-12.9.mbs1.noarch.rpm
8ea25400b2d708f2d7da22df4a5a6228 mbs1/x86_64/glibc-doc-pdf-2.14.1-12.9.mbs1.noarch.rpm
dfc7aae076e0a66b236968ee0af8e7da mbs1/x86_64/glibc-i18ndata-2.14.1-12.9.mbs1.x86_64.rpm
ebf493606c89def3d6bfca87749bbf03 mbs1/x86_64/glibc-profile-2.14.1-12.9.mbs1.x86_64.rpm
6ad78068de0280f4584d5e8b70890de5 mbs1/x86_64/glibc-static-devel-2.14.1-12.9.mbs1.x86_64.rpm
c796168f27f0236d7cd9123aba6e5ee8 mbs1/x86_64/glibc-utils-2.14.1-12.9.mbs1.x86_64.rpm
044ada512f6397981550cb3342a48173 mbs1/x86_64/nscd-2.14.1-12.9.mbs1.x86_64.rpm
5fc48f30a7f358c201b72be63a7a677d mbs1/SRPMS/glibc-2.14.1-12.9.mbs1.src.rpm
_______________________________________________________________________

To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/en/support/security/advisories/

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com
_______________________________________________________________________

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
<security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iD8DBQFUCX8NmqjQ0CJFipgRAqzxAJ9pVZoPY825wB33ukpXc3ofeE0xugCg0Gv0
gUv75jIjJhnMP0ZKVat47Bg=
=ijrN
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

October 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Oct 1st
    39 Files
  • 2
    Oct 2nd
    23 Files
  • 3
    Oct 3rd
    18 Files
  • 4
    Oct 4th
    20 Files
  • 5
    Oct 5th
    0 Files
  • 6
    Oct 6th
    0 Files
  • 7
    Oct 7th
    0 Files
  • 8
    Oct 8th
    0 Files
  • 9
    Oct 9th
    0 Files
  • 10
    Oct 10th
    0 Files
  • 11
    Oct 11th
    0 Files
  • 12
    Oct 12th
    0 Files
  • 13
    Oct 13th
    0 Files
  • 14
    Oct 14th
    0 Files
  • 15
    Oct 15th
    0 Files
  • 16
    Oct 16th
    0 Files
  • 17
    Oct 17th
    0 Files
  • 18
    Oct 18th
    0 Files
  • 19
    Oct 19th
    0 Files
  • 20
    Oct 20th
    0 Files
  • 21
    Oct 21st
    0 Files
  • 22
    Oct 22nd
    0 Files
  • 23
    Oct 23rd
    0 Files
  • 24
    Oct 24th
    0 Files
  • 25
    Oct 25th
    0 Files
  • 26
    Oct 26th
    0 Files
  • 27
    Oct 27th
    0 Files
  • 28
    Oct 28th
    0 Files
  • 29
    Oct 29th
    0 Files
  • 30
    Oct 30th
    0 Files
  • 31
    Oct 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close