• [SECURITY] [DSA 2976-1] eglibc security update

    From Florian Weimer@1:229/2 to All on Thu Jul 10 21:00:01 2014
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-2976-1 [email protected] http://www.debian.org/security/ Florian Weimer
    July 10, 2014 http://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : eglibc
    CVE ID : CVE-2014-0475

    Stephane Chazelas discovered that the GNU C library, glibc, processed
    ".." path segments in locale-related environment variables, possibly
    allowing attackers to circumvent intended restrictions, such as
    ForceCommand in OpenSSH, assuming that they can supply crafted locale
    settings.

    For the stable distribution (wheezy), this problem has been fixed in
    version 2.13-38+deb7u3.

    This update also includes changes previously scheduled for the next
    wheezy point release as version 2.13-38+deb7u2. See the Debian
    changelog for details.

    We recommend that you upgrade your eglibc packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: http://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.10 (GNU/Linux)

    iQEcBAEBAgAGBQJTvuPNAAoJEL97/wQC1SS+HI4H+wV4HS0n1cwGpgB6y/Q34Qo8 0Mh+lJRRDxCOwWFhPh2WQGZ7vZQpoN0EX19swHRLEvDyrJPpULITsp+WmxTLSAFJ 9MzLeD4kwCbZ8tESxV6C/SO8lDhV0oDKr6e7gdstCifG3KK2y6wa2jOtwa+Hv+vv jUoE6a0NlZ3dU7SYCk2M+G8Tbl1jbO9ise8Js1ANUl1b4ccGo9YXONjL0NcAqo1i SH5XZYLCjVJQl1ZytHmPzU7Yjwu2lspJFRmkeMJupWx0yZitW/5cHfuMfM8/1fnx 2AS0oMNXVOc42b7OqHAQ51uzgzWUP8U7Ng0IEmL1dIhedKl0BPQbx0rJvKwnK9c=
    =32zc
    -----END PGP SIGNATURE-----


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: https://lists.debian.org/[email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)