Gentoo Archives: gentoo-user-es

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: [gentoo-user-es] [gentoo-announce] GLSA: glibc (update)
Date: Fri, 27 Sep 2002 05:35:08
Message-Id: 200209271234.38211.aliz@gentoo.org
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - --------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT
6 - - --------------------------------------------------------------------
7
8 PACKAGE :glibc
9 SUMMARY :division by zero
10 DATE :2002-09-27 10:00 UTC
11
12 - - --------------------------------------------------------------------
13
14 Wolfram Gloger discovered that the sunrpc overflow bugfix unintentially
15 replaced potential integer overflows in connection with malloc() with
16 more likely divisions by zero.
17
18 DETAIL
19
20 The XDR (external data representation) libraries are used to provide
21 platform-independent methods for sending data from one system process to
22 another, typically over a network connection. Such routines are commonly
23 used in remote procedure call (RPC) implementations to provide transparency
24 to application programmers who need to use common interfaces to interact
25 with many different types of systems. The xdr_array() function in the XDR
26 library provided by Sun Microsystems contains an integer overflow that can
27 lead to improperly sized dynamic memory allocation. Subsequent problems like
28 buffer overflows may result, depending on how and where the vulnerable
29 xdr_array() function is used.
30
31 More information can be found at:
32
33 http://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCAN-2002-0391
34 http://www.kb.cert.org/vuls/id/192995
35
36 SOLUTION
37
38 It is recommended that all Gentoo Linux users who are running
39 sys-libs/glibc-2.2.5-r6 and earlier update their systems
40 as follows:
41
42 emerge rsync
43 emerge glibc
44 emerge clean
45
46 - - --------------------------------------------------------------------
47 aliz@g.o - GnuPG key is available at www.gentoo.org/~aliz
48 - - --------------------------------------------------------------------
49 -----BEGIN PGP SIGNATURE-----
50 Version: GnuPG v1.0.7 (GNU/Linux)
51
52 iD8DBQE9lDQ8fT7nyhUpoZMRArr3AJ9w0CkiYldpCUqf5WuXuDtBKbI/8wCeMsdL
53 dZXLcnQCUuKAIjwn0nRXHqk=
54 =vaoB
55 -----END PGP SIGNATURE-----
56
57 _______________________________________________
58 gentoo-announce mailing list
59 gentoo-announce@g.o
60 http://lists.gentoo.org/mailman/listinfo/gentoo-announce