Bug 156048
| Summary: | nscd vulnerable to cache poisoning | ||
|---|---|---|---|
| Product: | [Retired] Fedora Legacy | Reporter: | Need Real Name <kelson> |
| Component: | glibc | Assignee: | Fedora Legacy Bugs <bugs> |
| Status: | CLOSED DUPLICATE | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | rhl7.3 | CC: | fweimer |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | i386 | ||
| OS: | Linux | ||
| Whiteboard: | LEGACY, rh73, publish-rhl73 | ||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2005-05-05 06:42:02 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Need Real Name
2005-04-26 23:33:57 UTC
What do your /etc/hosts and /etc/nswitch.conf files contain? Relevant lines from... /etc/hosts: 127.0.0.1 localhost.localdomain localhost localhost.speed.net - I have since changed this to: 127.0.0.1 localhost localhost.localdomain /etc/nsswitch.conf: hosts: files dns Seems to be a known issue fixed in later versions of glibc...I'll try and find a patch... See bug 90463 and bug 56545 Looks like the glibc-2.2.4-nscd-hstcache.patch patch from glibc-2.2.4-32.18.src.rpm takes care of this issue. I'll build some test packages for rhl7.3 tomorrow. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Here are updated glibc packages to test/QA that may correct the issue: * Wed Apr 27 2005 Marc Deslauriers <marcdeslauriers> 2.2.4-44.legacy.4 - - Added patch so gethostbyaddr and gethostbyname don't use the same cache 2ed45236c3f1dc1ad090ca068b6ab9871ec7a0c2 glibc-2.2.5-44.legacy.4.i386.rpm d342ed96344b248e44a69fffab8ecfec7c5af3d1 glibc-2.2.5-44.legacy.4.i686.rpm caa130a388f5844de8d0f765c1af01afabb71ad3 glibc-2.2.5-44.legacy.4.src.rpm cdfa401bf9415547c5945ef1751a614856144e18 glibc-common-2.2.5-44.legacy.4.i386.rpm 7fea39b6b95b359dd876782a7a372577492942a1 glibc-debug-2.2.5-44.legacy.4.i386.rpm e47473b12c68fa09a7a100ffc5eb9f395c22e52f glibc-debug-2.2.5-44.legacy.4.i686.rpm f8cd5b999a8373a509a23adb71618dcf4c475d6e glibc-debug-static-2.2.5-44.legacy.4.i386.rpm 2fd3461497d86cb8d7abf3c135e42a255da027fa glibc-devel-2.2.5-44.legacy.4.i386.rpm 864c634b5adac25f5bab5d3ccf1d2923c4a19fbf glibc-profile-2.2.5-44.legacy.4.i386.rpm cb2221cb4c71a399dda76b9fe7338e6a6bfc8dfb glibc-utils-2.2.5-44.legacy.4.i386.rpm 46049abdeda819e1682d4deeda69f655a2131525 nscd-2.2.5-44.legacy.4.i386.rpm http://www.infostrategique.com/linuxrpms/legacy/7.3/glibc-2.2.5-44.legacy.4.i386.rpm http://www.infostrategique.com/linuxrpms/legacy/7.3/glibc-2.2.5-44.legacy.4.i686.rpm http://www.infostrategique.com/linuxrpms/legacy/7.3/glibc-2.2.5-44.legacy.4.src.rpm http://www.infostrategique.com/linuxrpms/legacy/7.3/glibc-common-2.2.5-44.legacy.4.i386.rpm http://www.infostrategique.com/linuxrpms/legacy/7.3/glibc-debug-2.2.5-44.legacy.4.i386.rpm http://www.infostrategique.com/linuxrpms/legacy/7.3/glibc-debug-2.2.5-44.legacy.4.i686.rpm http://www.infostrategique.com/linuxrpms/legacy/7.3/glibc-debug-static-2.2.5-44.legacy.4.i386.rpm http://www.infostrategique.com/linuxrpms/legacy/7.3/glibc-devel-2.2.5-44.legacy.4.i386.rpm http://www.infostrategique.com/linuxrpms/legacy/7.3/glibc-profile-2.2.5-44.legacy.4.i386.rpm http://www.infostrategique.com/linuxrpms/legacy/7.3/glibc-utils-2.2.5-44.legacy.4.i386.rpm http://www.infostrategique.com/linuxrpms/legacy/7.3/nscd-2.2.5-44.legacy.4.i386.rpm -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.6 (GNU/Linux) iD8DBQFCb82nLMAs/0C4zNoRAlt3AJ4uiL0F+m+RiIQWWHWRLZI+gpdNJQCeN4M6 skHXs07HwX6DfTiBgGwMrEI= =LpSt -----END PGP SIGNATURE----- I'll mark this one duplicate of #152848 so that we only need to track the glibc update in one place.. (I wonder if there's a better way to do these..) |