First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 17846
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Bug Hunter <tidoineurope@yahoo.com>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 17846 depends on: Show dependency tree
Bug 17846 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2003-03-19 16:37 0000
From the CERT advisory:

Overview:
There is an integer overflow in the xdrmem_getbytes() function distributed as
part of the Sun
Microsystems XDR library. This overflow can cause remotely exploitable buffer
overflows in multiple
applications, leading to the execution of arbitrary code. Although the library
was originally distributed by 
Sun Microsystems, multiple vendors have included the vulnerable code in their
own implementations. 

GNU glibc:
Version 2.3.1 of the GNU C Library is vulnerable. Earlier versions are also
vulnerable. The following
patches have been installed into the CVS sources, and should appear in the next
version of the GNU 
C Library. These patches are also available from the following URLs:

http://sources.redhat.com/cgi-bin/cvsweb.cgi/libc/sunrpc/rpc/xdr.h.diff?r1=1.26&r2=1.27&cvsroot=glibc
http://sources.redhat.com/cgi-bin/cvsweb.cgi/libc/sunrpc/xdr_mem.c.diff?r1=1.13&r2=1.15&cvsroot=glibc
http://sources.redhat.com/cgi-bin/cvsweb.cgi/libc/sunrpc/xdr_rec.c.diff?r1=1.26&r2=1.27&cvsroot=glibc
http://sources.redhat.com/cgi-bin/cvsweb.cgi/libc/sunrpc/xdr_sizeof.c.diff?r1=1.5&r2=1.6&cvsroot=glibc
http://sources.redhat.com/cgi-bin/cvsweb.cgi/libc/sunrpc/xdr_stdio.c.diff?r1=1.15&r2=1.16&cvsroot=glibc

------- Comment #1 From Daniel Ahlberg (RETIRED) 2003-03-21 04:50:38 0000 -------
Martin, I've added glibc-2.3.1-r4 (copied from 2.3.1-r3) with the patches to
the tree 
but I want your approval before I unmask it. Could you take a look and tell me
what 
you think? 

------- Comment #2 From Daniel Ahlberg (RETIRED) 2003-03-25 04:55:16 0000 -------
glsa sent 

First Last Prev Next    No search results available      Search page      Enter new bug