GNU C Library: Multiple vulnerabilities — GLSA 201503-04

Multiple vulnerabilities have been found in GNU C Library, the worst of which allowing a local attacker to execute arbitrary code or cause a Denial of Service .

Affected packages

sys-libs/glibc on all architectures
Affected versions < 2.19-r1
Unaffected versions >= 2.19-r1

Background

The GNU C library is the standard C library used by Gentoo Linux systems.

Description

Multiple vulnerabilities have been discovered in the GNU C Library. Please review the CVE identifiers referenced below for details.

Impact

A local attacker may be able to execute arbitrary code or cause a Denial of Service condition,.

Workaround

There is no known workaround at this time.

Resolution

All glibc users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=sys-libs/glibc-2.19-r1"
 

References

Release date
March 08, 2015

Latest revision
March 08, 2015: 1

Severity
normal

Exploitable
remote

Bugzilla entries