Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1262914 - (CVE-2015-5277) CVE-2015-5277 glibc: data corruption while reading the NSS files database
CVE-2015-5277 glibc: data corruption while reading the NSS files database
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
impact=important,public=20150914,repo...
: Security
Depends On: 1099235 1263134 1263352 1275920
Blocks: 1262918
  Show dependency treegraph
 
Reported: 2015-09-14 11:36 EDT by Florian Weimer
Modified: 2015-12-18 08:47 EST (History)
15 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
It was discovered that the nss_files backend for the Name Service Switch in glibc would return incorrect data to applications or corrupt the heap (depending on adjacent heap contents). A local attacker could potentially use this flaw to execute arbitrary code on the system.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2015-11-20 00:58:06 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Sourceware 17079 None None None Never
Red Hat Product Errata RHSA-2015:2172 normal SHIPPED_LIVE Important: glibc security update 2015-11-19 15:45:24 EST
Red Hat Product Errata RHSA-2015:2589 normal SHIPPED_LIVE Important: glibc security update 2015-12-09 08:57:25 EST

  None (edit)
Description Florian Weimer 2015-09-14 11:36:19 EDT
It was discovered that the nss_files backend for the Name Service Switch in glibc would return incorrect data to applications or corrupt the heap (depending on adjacent heap contents), potentially resulting in arbitrary code execution.
Comment 1 Florian Weimer 2015-09-14 11:37:37 EDT
External references:

https://sourceware.org/bugzilla/show_bug.cgi?id=17079
Comment 10 Ján Rusnačko 2015-11-13 03:38:59 EST
Acknowledgements:

This issue was discovered by Sumit Bose and Lukáš Slebodník of Red Hat.
Comment 11 errata-xmlrpc 2015-11-19 10:55:50 EST
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2015:2172 https://rhn.redhat.com/errata/RHSA-2015-2172.html
Comment 15 errata-xmlrpc 2015-12-09 03:58:49 EST
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7.1 EUS - Server and Compute Node Only
  Red Hat Enterprise Linux 7.1 EUS  - Server and Compute Node Only

Via RHSA-2015:2589 https://rhn.redhat.com/errata/RHSA-2015-2589.html

Note You need to log in before you can comment on or make changes to this bug.