RHSA-2010:0787: Important: glibc security update
The glibc packages contain the standard C libraries used by multipleprograms on the system. These packages contain the standard C and thestandard math libraries. Without these two libraries, a Linux system cannotfunction properly.It was discovered that the glibc dynamic linker/loader did not handle the$ORIGIN dynamic string token set in the LDAUDIT environment variablesecurely. A local attacker with write access to a file system containingsetuid or setgid binaries could use this flaw to escalate their privileges.(CVE-2010-3847)Red Hat would like to thank Tavis Ormandy for reporting this issue.All users should upgrade to these updated packages, which contain abackported patch to correct this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2010:0787?
The severity of RHSA-2010:0787 is classified as important.
How do I fix RHSA-2010:0787?
To fix RHSA-2010:0787, you need to upgrade the affected glibc packages to version 2.5-49.el5_5.6.
Which packages are affected by RHSA-2010:0787?
The affected packages include glibc, glibc-common, glibc-devel, glibc-headers, glibc-utils, and nscd.
Is it safe to ignore RHSA-2010:0787?
It is not recommended to ignore RHSA-2010:0787 as it may affect the stability and security of your Linux system.
When was RHSA-2010:0787 released?
RHSA-2010:0787 was released on May 25, 2010.