exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Mandriva Linux Security Advisory 2014-175

Mandriva Linux Security Advisory 2014-175
Posted Sep 8, 2014
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2014-175 - When converting IBM930 code with iconv(), if IBM930 code which includes invalid multibyte character 0xffff is specified, then iconv() segfaults. Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library allows context-dependent attackers to cause a denial of service or execute arbitrary code via vectors related to the CHARSET environment variable and gconv transliteration modules. Crashes were reported in the IBM code page decoding functions (IBM933, IBM935, IBM937, IBM939, IBM1364). The updated packages have been patched to correct these issues.

tags | advisory, denial of service, arbitrary
systems | linux, mandriva
advisories | CVE-2012-6656, CVE-2014-5119, CVE-2014-6040
SHA-256 | f3306f4d40c605cd5282642a6815dd2da169dca7f32fb2e4796c7ec5dcb10aa7

Mandriva Linux Security Advisory 2014-175

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDVSA-2014:175
http://www.mandriva.com/en/support/security/
_______________________________________________________________________

Package : glibc
Date : September 5, 2014
Affected: Business Server 1.0
_______________________________________________________________________

Problem Description:

Multiple vulnerabilities has been found and corrected in glibc:

When converting IBM930 code with iconv(), if IBM930 code which includes
invalid multibyte character 0xffff is specified, then iconv() segfaults
(CVE-2012-6656).

Off-by-one error in the __gconv_translit_find function in gconv_trans.c
in GNU C Library (aka glibc) allows context-dependent attackers to
cause a denial of service (crash) or execute arbitrary code via vectors
related to the CHARSET environment variable and gconv transliteration
modules (CVE-2014-5119).

Crashes were reported in the IBM code page decoding functions (IBM933,
IBM935, IBM937, IBM939, IBM1364) (CVE-2014-6040).

The updated packages have been patched to correct these issues.
_______________________________________________________________________

References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6656
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5119
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6040
https://rhn.redhat.com/errata/RHSA-2014-1110.html
https://sourceware.org/bugzilla/show_bug.cgi?id=14134
https://sourceware.org/bugzilla/show_bug.cgi?id=17325
http://seclists.org/oss-sec/2014/q3/485
https://bugzilla.redhat.com/show_bug.cgi?id=1135841
_______________________________________________________________________

Updated Packages:

Mandriva Business Server 1/X86_64:
85b7b4e252324a0590706605fe3a9d96 mbs1/x86_64/glibc-2.14.1-12.9.mbs1.x86_64.rpm
63cd91495f99e794eb0281b7c9ee2e32 mbs1/x86_64/glibc-devel-2.14.1-12.9.mbs1.x86_64.rpm
21d0709e256566ee526e9fbb0197b637 mbs1/x86_64/glibc-doc-2.14.1-12.9.mbs1.noarch.rpm
8ea25400b2d708f2d7da22df4a5a6228 mbs1/x86_64/glibc-doc-pdf-2.14.1-12.9.mbs1.noarch.rpm
dfc7aae076e0a66b236968ee0af8e7da mbs1/x86_64/glibc-i18ndata-2.14.1-12.9.mbs1.x86_64.rpm
ebf493606c89def3d6bfca87749bbf03 mbs1/x86_64/glibc-profile-2.14.1-12.9.mbs1.x86_64.rpm
6ad78068de0280f4584d5e8b70890de5 mbs1/x86_64/glibc-static-devel-2.14.1-12.9.mbs1.x86_64.rpm
c796168f27f0236d7cd9123aba6e5ee8 mbs1/x86_64/glibc-utils-2.14.1-12.9.mbs1.x86_64.rpm
044ada512f6397981550cb3342a48173 mbs1/x86_64/nscd-2.14.1-12.9.mbs1.x86_64.rpm
5fc48f30a7f358c201b72be63a7a677d mbs1/SRPMS/glibc-2.14.1-12.9.mbs1.src.rpm
_______________________________________________________________________

To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/en/support/security/advisories/

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com
_______________________________________________________________________

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
<security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iD8DBQFUCX8NmqjQ0CJFipgRAqzxAJ9pVZoPY825wB33ukpXc3ofeE0xugCg0Gv0
gUv75jIjJhnMP0ZKVat47Bg=
=ijrN
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

March 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Mar 1st
    16 Files
  • 2
    Mar 2nd
    0 Files
  • 3
    Mar 3rd
    0 Files
  • 4
    Mar 4th
    32 Files
  • 5
    Mar 5th
    28 Files
  • 6
    Mar 6th
    42 Files
  • 7
    Mar 7th
    17 Files
  • 8
    Mar 8th
    13 Files
  • 9
    Mar 9th
    0 Files
  • 10
    Mar 10th
    0 Files
  • 11
    Mar 11th
    15 Files
  • 12
    Mar 12th
    19 Files
  • 13
    Mar 13th
    21 Files
  • 14
    Mar 14th
    38 Files
  • 15
    Mar 15th
    15 Files
  • 16
    Mar 16th
    0 Files
  • 17
    Mar 17th
    0 Files
  • 18
    Mar 18th
    10 Files
  • 19
    Mar 19th
    0 Files
  • 20
    Mar 20th
    0 Files
  • 21
    Mar 21st
    0 Files
  • 22
    Mar 22nd
    0 Files
  • 23
    Mar 23rd
    0 Files
  • 24
    Mar 24th
    0 Files
  • 25
    Mar 25th
    0 Files
  • 26
    Mar 26th
    0 Files
  • 27
    Mar 27th
    0 Files
  • 28
    Mar 28th
    0 Files
  • 29
    Mar 29th
    0 Files
  • 30
    Mar 30th
    0 Files
  • 31
    Mar 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close