Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2015-01143

Опубликовано: 01 янв. 2015
Источник: fstec
CVSS2: 7.5
EPSS Низкий

Описание

Множественные уязвимости пакета libc6.1-udeb операционной системы Debian GNU/Linux, эксплуатация которых может привести к нарушению конфиденциальности, целостности и доступности защищаемой информации. Эксплуатация уязвимостей может быть осуществлена удаленно.

Вендор

Сообщество свободного программного обеспечения

Наименование ПО

Debian GNU/Linux

Версия ПО

до 5 (Debian GNU/Linux)

Тип ПО

Операционная система

Операционные системы и аппаратные платформы

-

Уровень опасности уязвимости

Высокий уровень опасности (базовая оценка CVSS 2.0 составляет 7,5)

Возможные меры по устранению уязвимости

Проблема может быть решена обновлением операционной системы до следующих версий пакетов в зависимости от архитектуры:
Debian GNU/Linux 5:
ppc:
libc6-ppc64 - 2.7-18lenny4
libnss-files-udeb - 2.7-18lenny4
libc6 - 2.7-18lenny4
libnss-dns-udeb - 2.7-18lenny4
locales-all - 2.7-18lenny4
libc6-dev-ppc64 - 2.7-18lenny4
libc6-pic - 2.7-18lenny4
libc6-dbg - 2.7-18lenny4
libc6-udeb - 2.7-18lenny4
nscd - 2.7-18lenny4
libc6-prof - 2.7-18lenny4
libc6-dev - 2.7-18lenny4
s390x:
libc6-dev-s390x - 2.7-18lenny4
libc6-dbg - 2.7-18lenny4
libc6-udeb - 2.7-18lenny4
libc6-dev - 2.7-18lenny4
libnss-dns-udeb - 2.7-18lenny4
libnss-files-udeb - 2.7-18lenny4
libc6-s390x - 2.7-18lenny4
libc6 - 2.7-18lenny4
libc6-pic - 2.7-18lenny4
libc6-prof - 2.7-18lenny4
locales-all - 2.7-18lenny4
nscd - 2.7-18lenny4
i686:
nscd - 2.7-18lenny4
libc6-udeb - 2.7-18lenny4
libc6 - 2.7-18lenny4
libc6-pic - 2.7-18lenny4
libnss-dns-udeb - 2.7-18lenny4
libc6-i686 - 2.7-18lenny4
libc6-dev - 2.7-18lenny4
locales-all - 2.7-18lenny4
libc6-xen - 2.7-18lenny4
libc6-amd64 - 2.7-18lenny4
libc6-prof - 2.7-18lenny4
libc6-dbg - 2.7-18lenny4
libc6-dev-amd64 - 2.7-18lenny4
libnss-files-udeb - 2.7-18lenny4
hppa:
libnss-files-udeb - 2.7-18lenny4
libc6-prof - 2.7-18lenny4
libc6-dbg - 2.7-18lenny4
libc6-udeb - 2.7-18lenny4
libnss-dns-udeb - 2.7-18lenny4
libc6-dev - 2.7-18lenny4
libc6-pic - 2.7-18lenny4
locales-all - 2.7-18lenny4
libc6 - 2.7-18lenny4
nscd - 2.7-18lenny4
sparc:
libc6-sparc64 - 2.7-18lenny4
nscd - 2.7-18lenny4
libnss-files-udeb - 2.7-18lenny4
libc6-udeb - 2.7-18lenny4
libc6-pic - 2.7-18lenny4
libc6-dev - 2.7-18lenny4
libc6 - 2.7-18lenny4
libc6-dev-sparc64 - 2.7-18lenny4
libc6-dbg - 2.7-18lenny4
libnss-dns-udeb - 2.7-18lenny4
libc6-prof - 2.7-18lenny4
locales-all - 2.7-18lenny4
libc6-sparcv9b - 2.7-18lenny4
x86-64:
libc6-dev-i386 - 2.7-18lenny4
locales-all - 2.7-18lenny4
libc6-i386 - 2.7-18lenny4
libc6-dbg - 2.7-18lenny4
libc6 - 2.7-18lenny4
libc6-prof - 2.7-18lenny4
libnss-dns-udeb - 2.7-18lenny4
nscd - 2.7-18lenny4
libc6-dev - 2.7-18lenny4
libc6-pic - 2.7-18lenny4
libnss-files-udeb - 2.7-18lenny4
libc6-udeb - 2.7-18lenny4
armel:
libc6-dbg - 2.7-18lenny4
libc6-prof - 2.7-18lenny4
libc6-udeb - 2.7-18lenny4
locales-all - 2.7-18lenny4
libc6-pic - 2.7-18lenny4
nscd - 2.7-18lenny4
libnss-dns-udeb - 2.7-18lenny4
libc6-dev - 2.7-18lenny4
libc6 - 2.7-18lenny4
libnss-files-udeb - 2.7-18lenny4
alpha:
libc6.1-pic - 2.7-18lenny4
libc6.1-dbg - 2.7-18lenny4
libnss-files-udeb - 2.7-18lenny4
libc6.1-dev - 2.7-18lenny4
libnss-dns-udeb - 2.7-18lenny4
libc6.1 - 2.7-18lenny4
libc6.1-prof - 2.7-18lenny4
nscd - 2.7-18lenny4
libc6.1-alphaev67 - 2.7-18lenny4
locales-all - 2.7-18lenny4
libc6.1-udeb - 2.7-18lenny4
ia64:
locales-all - 2.7-18lenny4
libc6.1-udeb - 2.7-18lenny4
libc6.1 - 2.7-18lenny4
libc6.1-dbg - 2.7-18lenny4
libnss-dns-udeb - 2.7-18lenny4
libc6.1-dev - 2.7-18lenny4
libc6.1-prof - 2.7-18lenny4
nscd - 2.7-18lenny4
libnss-files-udeb - 2.7-18lenny4
libc6.1-pic - 2.7-18lenny4
mips:
libc6-prof - 2.7-18lenny4
libc6-udeb - 2.7-18lenny4
locales-all - 2.7-18lenny4
libnss-dns-udeb - 2.7-18lenny4
libc6-dev-mips64 - 2.7-18lenny4
libc6-dev - 2.7-18lenny4
nscd - 2.7-18lenny4
libc6-mipsn32 - 2.7-18lenny4
libc6-mips64 - 2.7-18lenny4
libc6-dbg - 2.7-18lenny4
libc6-dev-mipsn32 - 2.7-18lenny4
libnss-files-udeb - 2.7-18lenny4
libc6-pic - 2.7-18lenny4
libc6 - 2.7-18lenny4
noarch:
glibc-source - 2.7-18lenny4
locales - 2.7-18lenny4
glibc-doc - 2.7-18lenny4
mipsel:
libc6-mips64 - 2.7-18lenny4
libc6-udeb - 2.7-18lenny4
nscd - 2.7-18lenny4
libnss-dns-udeb - 2.7-18lenny4
libc6-dev-mips64 - 2.7-18lenny4
libc6-dev-mipsn32 - 2.7-18lenny4
libc6 - 2.7-18lenny4
libnss-files-udeb - 2.7-18lenny4
libc6-pic - 2.7-18lenny4
libc6-prof - 2.7-18lenny4
libc6-dev - 2.7-18lenny4
libc6-mipsn32 - 2.7-18lenny4
locales-all - 2.7-18lenny4
libc6-dbg - 2.7-18lenny4
arm:
libnss-files-udeb - 2.7-18lenny4
libc6-dev - 2.7-18lenny4
locales-all - 2.7-18lenny4
libc6-udeb - 2.7-18lenny4
libc6-dbg - 2.7-18lenny4
nscd - 2.7-18lenny4
libc6-pic - 2.7-18lenny4
libc6 - 2.7-18lenny4
libnss-dns-udeb - 2.7-18lenny4
libc6-prof - 2.7-18lenny4

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

EPSS

Процентиль: 30%
0.00107
Низкий

7.5 High

CVSS2

Связанные уязвимости

ubuntu
около 15 лет назад

The encode_name macro in misc/mntent_r.c in the GNU C Library (aka glibc or libc6) 2.11.1 and earlier, as used by ncpmount and mount.cifs, does not properly handle newline characters in mountpoint names, which allows local users to cause a denial of service (mtab corruption), or possibly modify mount options and gain privileges, via a crafted mount request.

redhat
около 15 лет назад

The encode_name macro in misc/mntent_r.c in the GNU C Library (aka glibc or libc6) 2.11.1 and earlier, as used by ncpmount and mount.cifs, does not properly handle newline characters in mountpoint names, which allows local users to cause a denial of service (mtab corruption), or possibly modify mount options and gain privileges, via a crafted mount request.

nvd
около 15 лет назад

The encode_name macro in misc/mntent_r.c in the GNU C Library (aka glibc or libc6) 2.11.1 and earlier, as used by ncpmount and mount.cifs, does not properly handle newline characters in mountpoint names, which allows local users to cause a denial of service (mtab corruption), or possibly modify mount options and gain privileges, via a crafted mount request.

debian
около 15 лет назад

The encode_name macro in misc/mntent_r.c in the GNU C Library (aka gli ...

github
около 3 лет назад

The encode_name macro in misc/mntent_r.c in the GNU C Library (aka glibc or libc6) 2.11.1 and earlier, as used by ncpmount and mount.cifs, does not properly handle newline characters in mountpoint names, which allows local users to cause a denial of service (mtab corruption), or possibly modify mount options and gain privileges, via a crafted mount request.

EPSS

Процентиль: 30%
0.00107
Низкий

7.5 High

CVSS2