USN-3239-2: GNU C Library Regression

Published Mar 21, 2017
·
Updated

USN-3239-1 fixed vulnerabilities in the GNU C Library. Unfortunately, the fix for CVE-2015-5180 introduced an internal ABI change within the resolver library. This update reverts the change. We apologize for the inconvenience. Please note that long-running services that were restarted to compensate for the USN-3239-1 update may need to be restarted again. Original advisory details: It was discovered that the GNU C Library incorrectly handled the strxfrm() function. An attacker could use this issue to cause a denial of service or possibly execute arbitrary code. This issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2015-8982) It was discovered that an integer overflow existed in the IOwstroverflow() function of the GNU C Library. An attacker could use this to cause a denial of service or possibly execute arbitrary code. This issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2015-8983) It was discovered that the fnmatch() function in the GNU C Library did not properly handle certain malformed patterns. An attacker could use this to cause a denial of service. This issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2015-8984) Alexander Cherepanov discovered a stack-based buffer overflow in the glob implementation of the GNU C Library. An attacker could use this to specially craft a directory layout and cause a denial of service. (CVE-2016-1234) Florian Weimer discovered a NULL pointer dereference in the DNS resolver of the GNU C Library. An attacker could use this to cause a denial of service. (CVE-2015-5180) Michael Petlan discovered an unbounded stack allocation in the getaddrinfo() function of the GNU C Library. An attacker could use this to cause a denial of service. (CVE-2016-3706) Aldy Hernandez discovered an unbounded stack allocation in the sunrpc implementation in the GNU C Library. An attacker could use this to cause a denial of service. (CVE-2016-4429) Tim Ruehsen discovered that the getaddrinfo() implementation in the GNU C Library did not properly track memory allocations. An attacker could use this to cause a denial of service. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-5417) Andreas Schwab discovered that the GNU C Library on ARM 32-bit platforms did not properly set up execution contexts. An attacker could use this to cause a denial of service. (CVE-2016-6323)

Affected Software

6 affected componentsFixes available
All of the following
ubuntu/libc6<2.23-0ubuntu7
2.23-0ubuntu7
Ubuntu Ubuntu=16.04
All of the following
ubuntu/libc6<2.19-0ubuntu6.11
2.19-0ubuntu6.11
Ubuntu Ubuntu=14.04
All of the following
ubuntu/libc6<2.15-0ubuntu10.17
2.15-0ubuntu10.17
Ubuntu Ubuntu=12.04

Event History

Mar 21, 2017
Advisory Published
via Ubuntu·12:00 AM

Frequently Asked Questions

1

What vulnerabilities does USN-3239-2 address?

USN-3239-2 addresses issues related to the GNU C Library, specifically reverting a change that affected ABI in the resolver library.

2

What is the severity level of USN-3239-2?

The severity level of USN-3239-2 is not explicitly stated, but it is critical to ensure the integrity and functioning of affected systems.

3

Which Ubuntu versions are affected by USN-3239-2?

USN-3239-2 affects Ubuntu versions 16.04, 14.04, and 12.04 with specific libc6 package versions.

4

How do I remediate the issues fixed in USN-3239-2?

To remediate the issues fixed in USN-3239-2, it is recommended to update the libc6 package to the patched version specific to your Ubuntu release.

5

What should I be aware of regarding my services after applying USN-3239-2?

After applying USN-3239-2, be aware that long-running services may need to be restarted to fully incorporate the updates.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203