Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2017-1481

Опубликовано: 19 июн. 2017
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2017-1481: glibc security update (IMPORTANT)

[2.17-157.4]

  • Avoid large allocas in the dynamic linker (#1452720)

Обновленные пакеты

Oracle Linux 7

Oracle Linux x86_64

glibc

2.17-157.el7_3.4

glibc-common

2.17-157.el7_3.4

glibc-devel

2.17-157.el7_3.4

glibc-headers

2.17-157.el7_3.4

glibc-static

2.17-157.el7_3.4

glibc-utils

2.17-157.el7_3.4

nscd

2.17-157.el7_3.4

Связанные CVE

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 8 лет назад

glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these issues are not directly exploitable, as such they have not been given a CVE. This affects glibc 2.25 and earlier.

CVSS3: 7.4
redhat
больше 8 лет назад

glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these issues are not directly exploitable, as such they have not been given a CVE. This affects glibc 2.25 and earlier.

CVSS3: 7.8
nvd
больше 8 лет назад

glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these issues are not directly exploitable, as such they have not been given a CVE. This affects glibc 2.25 and earlier.

CVSS3: 7.8
debian
больше 8 лет назад

glibc contains a vulnerability that allows specially crafted LD_LIBRAR ...

suse-cvrf
больше 8 лет назад

Security update for glibc