Hide Forgot
It was discovered that the nss_files backend for the Name Service Switch in glibc would return incorrect data to applications or corrupt the heap (depending on adjacent heap contents), potentially resulting in arbitrary code execution.
External references: https://sourceware.org/bugzilla/show_bug.cgi?id=17079
Upstream commit: https://sourceware.org/git/gitweb.cgi?p=glibc.git;a=commitdiff;h=ac60763eac3d43b7234dd21286ad3ec3f17957fc
Acknowledgements: This issue was discovered by Sumit Bose and Lukáš Slebodník of Red Hat.
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2015:2172 https://rhn.redhat.com/errata/RHSA-2015-2172.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 7.1 EUS - Server and Compute Node Only Red Hat Enterprise Linux 7.1 EUS - Server and Compute Node Only Via RHSA-2015:2589 https://rhn.redhat.com/errata/RHSA-2015-2589.html