Oval Definition:oval:com.redhat.rhsa:def:20131652
Revision Date:2013-11-21Version:641
Title:RHSA-2013:1652: coreutils security, bug fix, and enhancement update (Low)
Description:The coreutils package contains the core GNU utilities. It is a combination of the old GNU fileutils, sh-utils, and textutils packages.

  • It was discovered that the sort, uniq, and join utilities did not properly restrict the use of the alloca() function. An attacker could use this flaw to crash those utilities by providing long input strings. (CVE-2013-0221, CVE-2013-0222, CVE-2013-0223)

    These updated coreutils packages include numerous bug fixes and two enhancements. Space precludes documenting all of these changes in this advisory. Users are directed to the Red Hat Enterprise Linux 6.5 Technical Notes, linked to in the References, for information on the most significant of these changes.

    All coreutils users are advised to upgrade to these updated packages, which contain backported patches to correct these issues and add these enhancements.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2013-0221
    CVE-2013-0222
    CVE-2013-0223
    RHSA-2013:1652
    RHSA-2013:1652-02
    RHSA-2013:1652-02
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • coreutils is earlier than 0:8.4-31.el6
  • AND coreutils is signed with Red Hat redhatrelease2 key
  • coreutils-libs is earlier than 0:8.4-31.el6
  • AND coreutils-libs is signed with Red Hat redhatrelease2 key
  • BACK