Bug 682991 - iconv regression
Summary: iconv regression
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 5
Classification: Red Hat
Component: glibc
Version: 5.6
Hardware: x86_64
OS: Linux
high
high
Target Milestone: rc
: ---
Assignee: Andreas Schwab
QA Contact: qe-baseos-tools-bugs
URL:
Whiteboard:
: 660217 (view as bug list)
Depends On: 670988
Blocks: CVE-2011-0536
TreeView+ depends on / blocked
 
Reported: 2011-03-08 08:55 UTC by RHEL Program Management
Modified: 2018-11-14 16:13 UTC (History)
10 users (show)

Fixed In Version: glibc-2.5-58.el5_6.1
Doc Type: Bug Fix
Doc Text:
The RHSA-2010:0787 security advisory completely disabled the expansion of the "$ORIGIN" dynamic string token in "RPATH" elements for privileged programs. However, this rendered certain libraries such as gconv unable to work properly. Since the expansion of "$ORIGIN" in "RPATH" elements does not pose a security threat when used in libraries, this update re-enables this feature for libraries, ensuring that gconv and others now work as expected.
Clone Of:
Environment:
Last Closed: 2011-04-04 20:06:41 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2011:0412 0 normal SHIPPED_LIVE Important: glibc security update 2011-04-04 20:06:07 UTC

Description RHEL Program Management 2011-03-08 08:55:06 UTC
This bug has been copied from bug #670988 and has been proposed
to be backported to 5.6 z-stream (EUS).

Comment 5 Jaromir Hradilek 2011-03-14 13:51:35 UTC
    Technical note added. If any revisions are required, please edit the "Technical Notes" field
    accordingly. All revisions will be proofread by the Engineering Content Services team.
    
    New Contents:
The RHSA-2010:0787 security advisory completely disabled the expansion of the "$ORIGIN" dynamic string token in "RPATH" elements for privileged programs. However, this rendered certain libraries such as gconv unable to work properly. Since the expansion of "$ORIGIN" in "RPATH" elements does not pose a security threat when used in libraries, this update re-enables this feature for libraries, ensuring that gconv and others now work as expected.

Comment 6 Tomas Hoger 2011-03-21 09:43:17 UTC
*** Bug 660217 has been marked as a duplicate of this bug. ***

Comment 8 errata-xmlrpc 2011-04-04 20:06:41 UTC
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on therefore solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.

http://rhn.redhat.com/errata/RHSA-2011-0412.html


Note You need to log in before you can comment on or make changes to this bug.