Univention Bugzilla – Bug 44860
glibc: Multiple issues (4.2)
Last modified: 2018-04-18 14:15:53 CEST
Upstream Debian package version 2.19-18+deb8u10 fixes these issues: * glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these issues are not directly exploitable, as such they have not been given a CVE (CVE-2017-1000366)
Mass-import from Debian-Security: python -m univention.repong.^Cbmirror -s jessie -r 4.2-3 --override=$HOME/REPOS/repo-ng/mirror/update_ucs42_mirror_from_debian.yml --errata=doc/errata --sql --process=ALL -vvvv --now=201801211553 YAML: git:bd6159834a..449aa5a7cf
Verified: * Upstream binary imported into errata4.2-3 * No additional UCS patches in 4.2 * package update Ok * Advisory: Ok
<http://errata.software-univention.de/ucs/4.2/333.html>