GNU C Library: Multiple vulnerabilities
Dan Johansson <[email protected]>
| Newsgroups | gmane.comp.security.ipcop.user |
|---|---|
| Message-ID | <[email protected]> |
Hi All, Does anyone here know if IPCop (2.1.9) is affected by these glibc vulnerabilities: * The Google Security Team and Red Hat discovered a stack-based buffer overflow in the send_dg() and send_vc() functions due to a buffer mismanagement when getaddrinfo() is called with AF_UNSPEC (CVE-2015-7547). * The strftime() function access invalid memory when passed out-of-range data, resulting in a crash (CVE-2015-8776). * An integer overflow was found in the __hcreate_r() function (CVE-2015-8778). * Multiple unbounded stack allocations were found in the catopen() function (CVE-2015-8779). Regards, -- Dan Johansson *************************************************** This message is printed on 100% recycled electrons! *************************************************** ------------------------------------------------------------------------------ Site24x7 APM Insight: Get Deep Visibility into Application Performance APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month Monitor end-to-end web transactions and take corrective actions now Troubleshoot faster and improve end-user experience. Signup Now! http://pubads.g.doubleclick.net/gampad/clk?id=272487151&iu=/4140 _______________________________________________ IPCop-user mailing list [email protected] Manage your subscription or unsubscribe https://lists.sourceforge.net/lists/listinfo/ipcop-user