[ubuntu/trusty-security] eglibc 2.19-0ubuntu6.13 (Accepted)
Marc Deslauriers
marc.deslauriers at canonical.com
Mon Jun 19 15:29:43 UTC 2017
eglibc (2.19-0ubuntu6.13) trusty-security; urgency=medium
* SECURITY UPDATE: LD_LIBRARY_PATH stack corruption
- debian/patches/any/CVE-2017-1000366.patch: Completely ignore
LD_LIBRARY_PATH for AT_SECURE=1 programs
- CVE-2017-1000366
* SECURITY UPDATE: LD_PRELOAD stack corruption
- debian/patches/any/upstream-harden-rtld-Reject-overly-long-LD_PRELOAD.patch:
Reject overly long names or names containing directories in
LD_PRELOAD for AT_SECURE=1 programs.
* debian/patches/any/cvs-harden-glibc-malloc-metadata.patch: add
additional consistency check for 1-byte overflows
* debian/patches/any/cvs-harden-ignore-LD_HWCAP_MASK.patch: ignore
LD_HWCAP_MASK for AT_SECURE=1 programs
Date: 2017-06-16 19:41:15.151815+00:00
Changed-By: Steve Beattie <sbeattie at ubuntu.com>
Signed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.13
-------------- next part --------------
Sorry, changesfile not available.
More information about the Trusty-changes
mailing list