USN-2985-1: GNU C Library vulnerabilities
USN-2985-1: GNU C Library vulnerabilities Ubuntu Security Notice USN-2985-1 25th May, 2016 eglibc, glibc vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 15.10 Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary Several security issues were fixed in the GNU C Library. Software description eglibc – GNU C Library glibc – GNU C Library Details Martin Carpenter discovered that pt_chown in the GNU C Library did notproperly check permissions for tty files. A local attacker could use thisto gain administrative privileges or expose sensitive information.(CVE-2013-2207, CVE-2016-2856) Robin Hack discovered that the Name Service Switch (NSS) implementation inthe GNU C Library did not properly manage its file descriptors. An attackercould use this to cause a denial of service (infinite loop).(CVE-2014-8121) Joseph Myers discovered that the GNU C Library did not properly handle longarguments to functions returning a representation [ more… ]