Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | |||
Test ID: | 1.3.6.1.4.1.25623.1.1.4.2014.1125.1 |
Category: | SuSE Local Security Checks |
Title: | SUSE: Security Advisory (SUSE-SU-2014:1125-1) |
Summary: | The remote host is missing an update for the 'glibc' package(s) announced via the SUSE-SU-2014:1125-1 advisory. |
Description: | Summary: The remote host is missing an update for the 'glibc' package(s) announced via the SUSE-SU-2014:1125-1 advisory. Vulnerability Insight: This glibc update fixes a critical privilege escalation problem and two non-security issues: * bnc#892073: An off-by-one error leading to a heap-based buffer overflow was found in __gconv_translit_find(). An exploit that targets the problem is publicly available. (CVE-2014-5119) * bnc#892065: setenv-alloca.patch: Avoid unbound alloca in setenv. * bnc#888347: printf-multibyte-format.patch: Don't parse %s format argument as multi-byte string. Security Issues: * CVE-2014-5119 Affected Software/OS: 'glibc' package(s) on SUSE Linux Enterprise Desktop 11 SP3, SUSE Linux Enterprise Server 11 SP3, SUSE Linux Enterprise Software Development Kit 11 SP3. Solution: Please install the updated package(s). CVSS Score: 7.5 CVSS Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2014-5119 BugTraq ID: 68983 http://www.securityfocus.com/bid/68983 BugTraq ID: 69738 http://www.securityfocus.com/bid/69738 Cisco Security Advisory: 20140910 Cisco Unified Communications Manager glibc Arbitrary Code Execution Vulnerability http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-5119 Debian Security Information: DSA-3012 (Google Search) http://www.debian.org/security/2014/dsa-3012 http://seclists.org/fulldisclosure/2014/Aug/69 https://security.gentoo.org/glsa/201602-02 http://www.mandriva.com/security/advisories?name=MDVSA-2014:175 http://googleprojectzero.blogspot.com/2014/08/the-poisoned-nul-byte-2014-edition.html https://code.google.com/p/google-security-research/issues/detail?id=96 http://www.openwall.com/lists/oss-security/2014/08/13/5 http://www.openwall.com/lists/oss-security/2014/07/14/1 RedHat Security Advisories: RHSA-2014:1110 https://rhn.redhat.com/errata/RHSA-2014-1110.html RedHat Security Advisories: RHSA-2014:1118 http://rhn.redhat.com/errata/RHSA-2014-1118.html http://secunia.com/advisories/60345 http://secunia.com/advisories/60358 http://secunia.com/advisories/60441 http://secunia.com/advisories/61074 http://secunia.com/advisories/61093 SuSE Security Announcement: SUSE-SU-2014:1125 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00017.html |
Copyright | Copyright (C) 2021 Greenbone Networks GmbH |
This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |