Opened 13 years ago

Closed 13 years ago

#2790 closed task (fixed)

glibc security patches

Reported by: bdubbs@… Owned by: Matthew Burgess
Priority: normal Milestone: 6.8
Component: Book Version: SVN
Severity: normal Keywords:
Cc:

Description

We should probably add two security patches:

  • glibc-2.12.1-ld_audit_fix-1.patch

Fixes a security vulnerability and makes LD_AUDIT behave same as LD_PRELOAD

  • glibc-2.12.1-origin_fix-1.patch

Fixes a security vulnerability, described in detail at

http://marc.info/?l=full-disclosure&m=128739684614072&w=2,

which allows a local attacker to gain root if they can create a hard link to a setuid root binary.

Both are in the patches repository.

Change History (2)

comment:1 by Matthew Burgess, 13 years ago

Owner: changed from lfs-book@… to Matthew Burgess
Status: newassigned

comment:2 by Matthew Burgess, 13 years ago

Resolution: fixed
Status: assignedclosed

Fixed in r9414.

Note: See TracTickets for help on using tickets.