exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Mandriva Linux Security Advisory 2014-175

Mandriva Linux Security Advisory 2014-175
Posted Sep 8, 2014
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2014-175 - When converting IBM930 code with iconv(), if IBM930 code which includes invalid multibyte character 0xffff is specified, then iconv() segfaults. Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library allows context-dependent attackers to cause a denial of service or execute arbitrary code via vectors related to the CHARSET environment variable and gconv transliteration modules. Crashes were reported in the IBM code page decoding functions (IBM933, IBM935, IBM937, IBM939, IBM1364). The updated packages have been patched to correct these issues.

tags | advisory, denial of service, arbitrary
systems | linux, mandriva
advisories | CVE-2012-6656, CVE-2014-5119, CVE-2014-6040
SHA-256 | f3306f4d40c605cd5282642a6815dd2da169dca7f32fb2e4796c7ec5dcb10aa7

Mandriva Linux Security Advisory 2014-175

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDVSA-2014:175
http://www.mandriva.com/en/support/security/
_______________________________________________________________________

Package : glibc
Date : September 5, 2014
Affected: Business Server 1.0
_______________________________________________________________________

Problem Description:

Multiple vulnerabilities has been found and corrected in glibc:

When converting IBM930 code with iconv(), if IBM930 code which includes
invalid multibyte character 0xffff is specified, then iconv() segfaults
(CVE-2012-6656).

Off-by-one error in the __gconv_translit_find function in gconv_trans.c
in GNU C Library (aka glibc) allows context-dependent attackers to
cause a denial of service (crash) or execute arbitrary code via vectors
related to the CHARSET environment variable and gconv transliteration
modules (CVE-2014-5119).

Crashes were reported in the IBM code page decoding functions (IBM933,
IBM935, IBM937, IBM939, IBM1364) (CVE-2014-6040).

The updated packages have been patched to correct these issues.
_______________________________________________________________________

References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6656
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5119
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6040
https://rhn.redhat.com/errata/RHSA-2014-1110.html
https://sourceware.org/bugzilla/show_bug.cgi?id=14134
https://sourceware.org/bugzilla/show_bug.cgi?id=17325
http://seclists.org/oss-sec/2014/q3/485
https://bugzilla.redhat.com/show_bug.cgi?id=1135841
_______________________________________________________________________

Updated Packages:

Mandriva Business Server 1/X86_64:
85b7b4e252324a0590706605fe3a9d96 mbs1/x86_64/glibc-2.14.1-12.9.mbs1.x86_64.rpm
63cd91495f99e794eb0281b7c9ee2e32 mbs1/x86_64/glibc-devel-2.14.1-12.9.mbs1.x86_64.rpm
21d0709e256566ee526e9fbb0197b637 mbs1/x86_64/glibc-doc-2.14.1-12.9.mbs1.noarch.rpm
8ea25400b2d708f2d7da22df4a5a6228 mbs1/x86_64/glibc-doc-pdf-2.14.1-12.9.mbs1.noarch.rpm
dfc7aae076e0a66b236968ee0af8e7da mbs1/x86_64/glibc-i18ndata-2.14.1-12.9.mbs1.x86_64.rpm
ebf493606c89def3d6bfca87749bbf03 mbs1/x86_64/glibc-profile-2.14.1-12.9.mbs1.x86_64.rpm
6ad78068de0280f4584d5e8b70890de5 mbs1/x86_64/glibc-static-devel-2.14.1-12.9.mbs1.x86_64.rpm
c796168f27f0236d7cd9123aba6e5ee8 mbs1/x86_64/glibc-utils-2.14.1-12.9.mbs1.x86_64.rpm
044ada512f6397981550cb3342a48173 mbs1/x86_64/nscd-2.14.1-12.9.mbs1.x86_64.rpm
5fc48f30a7f358c201b72be63a7a677d mbs1/SRPMS/glibc-2.14.1-12.9.mbs1.src.rpm
_______________________________________________________________________

To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/en/support/security/advisories/

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com
_______________________________________________________________________

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
<security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iD8DBQFUCX8NmqjQ0CJFipgRAqzxAJ9pVZoPY825wB33ukpXc3ofeE0xugCg0Gv0
gUv75jIjJhnMP0ZKVat47Bg=
=ijrN
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    18 Files
  • 19
    Nov 19th
    7 Files
  • 20
    Nov 20th
    13 Files
  • 21
    Nov 21st
    6 Files
  • 22
    Nov 22nd
    48 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    60 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    44 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close