glibc-2.5-49.7.0.1.AXS3
エラータID: AXSA:2010-477:06
リリース日:
2010/10/28 Thursday - 15:00
題名:
glibc-2.5-49.7.0.1.AXS3
影響のあるチャネル:
Asianux Server 3 for x86_64
Asianux Server 3 for x86
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- 現時点では CVE-2010-3856 の情報が公開されておりません。
CVEの情報が公開され次第情報をアップデートいたします。
一部CVEの翻訳文はJVNからの引用になります。
http://jvndb.jvn.jp/
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2010-3856
ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use of the LD_AUDIT environment variable to reference dynamic shared objects (DSOs) as audit objects, which allows local users to gain privileges by leveraging an unsafe DSO located in a trusted library directory, as demonstrated by libpcprofile.so.
ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use of the LD_AUDIT environment variable to reference dynamic shared objects (DSOs) as audit objects, which allows local users to gain privileges by leveraging an unsafe DSO located in a trusted library directory, as demonstrated by libpcprofile.so.
追加情報:
N/A
ダウンロード:
SRPMS
- glibc-2.5-49.7.0.1.AXS3.src.rpm
MD5: 2b1a2d9a3c30cd7ef02781c911ff397b
SHA-256: 13222f4b2a21d1e8355583f6b8cd4ecb4645d95742c065e48fb7c4d4af24c668
Size: 15.70 MB
Asianux Server 3 for x86
- glibc-2.5-49.7.0.1.AXS3.i686.rpm
MD5: d7433c57f3b88238adf7d768e857238d
SHA-256: dcec4f04c6efeb0b3219b750133e7279f3a05ce694a42e83c99384bb81347883
Size: 5.34 MB - glibc-2.5-49.7.0.1.AXS3.i386.rpm
MD5: b1ccdfcedca0fdfd250e2c2a6eadf251
SHA-256: f1dc7374ab5476f6dc094f8691ed0ff8a761a006ab889073a4fc67a00cfeb58c
Size: 4.48 MB - glibc-common-2.5-49.7.0.1.AXS3.i386.rpm
MD5: 18020ba0e2a957a3ba8a0fdf844620a7
SHA-256: 1f9bc00f21ed44a7034af1a0ec492e60723bc39b26398a951619ea6b1dcafadb
Size: 16.81 MB - glibc-devel-2.5-49.7.0.1.AXS3.i386.rpm
MD5: 92a8bcf97406355c07140d5d570ae433
SHA-256: eb6ea244026c9f659313c8e180233e8f05d89050385390b9df8e41bd666b8237
Size: 2.04 MB - glibc-headers-2.5-49.7.0.1.AXS3.i386.rpm
MD5: eb7b320495ea8caa5e3920efa5fc9ce8
SHA-256: 3c4474c50764d718d04377f8cdc343fdceedceafe234991f339d95a958e52fb1
Size: 613.05 kB - glibc-utils-2.5-49.7.0.1.AXS3.i386.rpm
MD5: dc32edac95e1d48ffca004fe00397a37
SHA-256: 6f21556b606817710d9b3d6196ef232005efd48e2709ffd6270a7c9133ac3c4b
Size: 132.06 kB - nscd-2.5-49.7.0.1.AXS3.i386.rpm
MD5: 1256b02defa2d1a4790bfd0a79e10f92
SHA-256: c0631a2faa4d6ae26b4c58fecc2b1bb83f7886ff8542e064a666e6123229291e
Size: 166.40 kB
Asianux Server 3 for x86_64
- glibc-2.5-49.7.0.1.AXS3.x86_64.rpm
MD5: 85a60657217bf00b6d607ca0b290dc72
SHA-256: 63cb96c019007cc47d9800f0ee3f9a545c21a540386f6c471e9d3ed1b4ccaec4
Size: 4.76 MB - glibc-common-2.5-49.7.0.1.AXS3.x86_64.rpm
MD5: 9d1c9fdb13ebd1868d15060a378f5c90
SHA-256: 70cab6303c3148e2de1c5158c00cb815127cac575496e9e29b21e73d760ba2ae
Size: 16.83 MB - glibc-devel-2.5-49.7.0.1.AXS3.x86_64.rpm
MD5: 9efb5c185aa351f4bb6a1281744ec6f8
SHA-256: 3a1151ed6888ee8c972767805b589a2302ebfd1e62e47e52a4d7d25ab40943c7
Size: 2.41 MB - glibc-headers-2.5-49.7.0.1.AXS3.x86_64.rpm
MD5: 832efcd85f24c72b95bbbd3bb6c40c71
SHA-256: 397803846f97ff6ce85cfe5d5a62b6a8db769f11b20a48a1123a2bc902f64b55
Size: 603.29 kB - glibc-utils-2.5-49.7.0.1.AXS3.x86_64.rpm
MD5: 42be32465145a214ee94c6126b4d2266
SHA-256: 0f471047ba7a573395b7f9dd81774601b71486ec617575517686c52c6d589e9b
Size: 130.60 kB - nscd-2.5-49.7.0.1.AXS3.x86_64.rpm
MD5: b195f4fe611a0ef0a6bc7c088a5bf722
SHA-256: 98c8e98fae5114230563632c6be7bcaa8d1fb3512cdad9eb8d14d16b6b4d0e61
Size: 166.64 kB