--------------------------------------------------------------------------
Turbolinux Security Advisory TLSA-2002-53
http://www/turbolinux.co.jp/security/
security-team@turbolinux.co.jp
--------------------------------------------------------------------------
Glibc
Buffer overflow problem
Release date : 2002-08-21
Solution: package : glibc-2.2.4-11
Problem
Buffer overflow problem exists in the SUN RPC XDR library of previous glibc 2.2.5, and there is a possibility of root authority being captured by unauthorized user.
Solution:
Please verify version and execute the command below.
# rpm -qa | grep package name
When problem corresponds, please download the update package. Do the update by the using the command below.
Furthermore, please execute the package number which corresponds to your version number. Without starting a new paragraph, please enter the "\ " Bunchu sign.
Execution example
---------------------------------------------------------------------
# rpm -Fvh Package-1.0.0-1.i586.rpm \
Package-doc-1.0.0-1.i586.rpm \
Package-devel-1.0.0-1.i586.rpm
The case where rpm command is executed, please enter as follows on the command line.
# rpm -Fvh package-1.0.0-1.i586.rpm package-doc-1.0.0-1.i586.rpm package-devel-1.0.0-1.i586.rpm
---------------------------------------------------------------------
< Turbolinux 8 Workstation >
* Because glibc 2.2.5 is adopted, there is no problem.
< Turbolinux 7 Server >
< Turbolinux 7 Workstation >
# rpm -Fvh glibc-2.2.4-11.i586.rpm \
glibc-devel-2.2.4-11.i586.rpm \
glibc-profile-2.2.4-11.i586.rpm \
mtrace-2.2.4-11.i586.rpm \
nscd-2.2.4-11.i586.rpm
< Turbolinux Server 6.5 >
< Turbolinux Advanced Server 6 >
< Turbolinux Server 6.1 >
< Turbolinux Workstation 6.0 >
# rpm -Fvh glibc-2.1.3-36.i386.rpm \
glibc-devel-2.1.3-36.i386.rpm \
glibc-profile-2.1.3-36.i386.rpm \
mtrace-2.1.3-36.i386.rpm \
nscd-2.1.3-36.i386.rpm
Package updates:
http://www.turbolinux.co.jp/update/