Oval Definition:oval:org.mitre.oval:def:28049
Revision Date:2014-12-15Version:9
Title:ELSA-2011-1526 -- glibc security, bug fix, and enhancement update (low)
Description:A flaw was found in the way the ldd utility identified dynamically linkedlibraries. If an attacker could trick a user into running ldd on amalicious binary, it could result in arbitrary code execution with theprivileges of the user running ldd. (CVE-2009-5064)It was found that the glibc addmntent() function, used by various mounthelper utilities, did not handle certain errors correctly when updating themtab (mounted file systems table) file. If such utilities had the setuidbit set, a local attacker could use this flaw to corrupt the mtab file.(CVE-2011-1089)
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2009-5064
CVE-2011-1089
ELSA-2011-1526
Platform(s):Oracle Linux 6
Product(s):glibc
Definition Synopsis
  • Oracle Linux 6.x
  • AND Packages match section
  • glibc is earlier than 0:2.12-1.47.el6
  • OR glibc-common is earlier than 0:2.12-1.47.el6
  • OR glibc-devel is earlier than 0:2.12-1.47.el6
  • OR glibc-headers is earlier than 0:2.12-1.47.el6
  • OR glibc-static is earlier than 0:2.12-1.47.el6
  • OR glibc-utils is earlier than 0:2.12-1.47.el6
  • OR nscd is earlier than 0:2.12-1.47.el6
  • BACK