glibc: Important security and bug fix update

Users of glibc please be advised of an Important security and bug fix update that has been identified.
To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx)

RHSA-2010:0872-02: [RHSA-2010:0872-02] Important: glibc security and bug fix update
Product: Red Hat Enterprise Linux
Description:

The glibc packages contain the standard C libraries used by multiple

programs on the system. These packages contain the standard C and the

standard math libraries. Without these two libraries, a Linux system

cannot function properly.

It was discovered that the glibc dynamic linker/loader did not handle the

$ORIGIN dynamic string token set in the LD_AUDIT environment variable

securely. A local attacker with write access to a file system containing

setuid or setgid binaries could use this flaw to escalate their privileges.

(CVE-2010-3847)

It was discovered that the glibc dynamic linker/loader did not perform

sufficient safety checks when loading dynamic shared objects (DSOs) to

provide callbacks for its auditing API during the execution of privileged

programs. A local attacker could use this flaw to escalate their privileges

via a carefully-chosen system DSO library containing unsafe constructors.

(CVE-2010-3856)
Read more at http://www.criticalwatch.com
 

Advertisements