First published: Wed Oct 20 2010(Updated: )
The glibc packages contain the standard C libraries used by multiple<br>programs on the system. These packages contain the standard C and the<br>standard math libraries. Without these two libraries, a Linux system cannot<br>function properly.<br>It was discovered that the glibc dynamic linker/loader did not handle the<br>$ORIGIN dynamic string token set in the LD_AUDIT environment variable<br>securely. A local attacker with write access to a file system containing<br>setuid or setgid binaries could use this flaw to escalate their privileges.<br>(CVE-2010-3847)<br>Red Hat would like to thank Tavis Ormandy for reporting this issue.<br>All users should upgrade to these updated packages, which contain a<br>backported patch to correct this issue.<br>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/glibc | <2.5-49.el5_5.6 | 2.5-49.el5_5.6 |
redhat/glibc | <2.5-49.el5_5.6 | 2.5-49.el5_5.6 |
redhat/glibc-common | <2.5-49.el5_5.6 | 2.5-49.el5_5.6 |
redhat/glibc-devel | <2.5-49.el5_5.6 | 2.5-49.el5_5.6 |
redhat/glibc-devel | <2.5-49.el5_5.6 | 2.5-49.el5_5.6 |
redhat/glibc-headers | <2.5-49.el5_5.6 | 2.5-49.el5_5.6 |
redhat/glibc-utils | <2.5-49.el5_5.6 | 2.5-49.el5_5.6 |
redhat/nscd | <2.5-49.el5_5.6 | 2.5-49.el5_5.6 |
redhat/glibc-common | <2.5-49.el5_5.6 | 2.5-49.el5_5.6 |
redhat/glibc-headers | <2.5-49.el5_5.6 | 2.5-49.el5_5.6 |
redhat/glibc-utils | <2.5-49.el5_5.6 | 2.5-49.el5_5.6 |
redhat/nscd | <2.5-49.el5_5.6 | 2.5-49.el5_5.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.