• [gentoo-announce] [ GLSA 202405-17 ] glibc: Multiple Vulnerabilities

    From [email protected]@21:1/5 to All on Wed May 8 11:30:02 2024
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    Gentoo Linux Security Advisory GLSA 202405-17
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    https://security.gentoo.org/
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Severity: High
    Title: glibc: Multiple Vulnerabilities
    Date: May 06, 2024
    Bugs: #930177, #930667
    ID: 202405-17

    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Synopsis
    ========

    Multiple vulnerabilities have been discovered in glibc, the worst of
    which could lead to remote code execution.

    Background
    ==========

    glibc is a package that contains the GNU C library.

    Affected packages
    =================

    Package Vulnerable Unaffected
    -------------- ------------ ------------
    sys-libs/glibc < 2.38-r13 >= 2.38-r13

    Description
    ===========

    Multiple vulnerabilities have been discovered in glibc. Please review
    the CVE identifiers referenced below for details.

    Impact
    ======

    Please review the referenced CVE identifiers for details.

    Workaround
    ==========

    There is no known workaround at this time.

    Resolution
    ==========

    All glibc users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=sys-libs/glibc-2.38-r13"

    References
    ==========

    [ 1 ] CVE-2024-2961
    https://nvd.nist.gov/vuln/detail/CVE-2024-2961
    [ 2 ] CVE-2024-33599
    https://nvd.nist.gov/vuln/detail/CVE-2024-33599
    [ 3 ] CVE-2024-33600
    https://nvd.nist.gov/vuln/detail/CVE-2024-33600
    [ 4 ] CVE-2024-33601
    https://nvd.nist.gov/vuln/detail/CVE-2024-33601
    [ 5 ] CVE-2024-33602
    https://nvd.nist.gov/vuln/detail/CVE-2024-33602
    [ 6 ] GLIBC-SA-2024-0004
    [ 7 ] GLIBC-SA-2024-0005
    [ 8 ] GLIBC-SA-2024-0006
    [ 9 ] GLIBC-SA-2024-0007
    [ 10 ] GLIBC-SA-2024-0008

    Availability
    ============

    This GLSA and any updates to it are available for viewing at
    the Gentoo Security Website:

    https://security.gentoo.org/glsa/202405-17

    Concerns?
    =========

    Security is a primary focus of Gentoo Linux and ensuring the
    confidentiality and security of our users' machines is of utmost
    importance to us. Any security concerns should be addressed to [email protected] or alternatively, you may file a bug at https://bugs.gentoo.org.

    License
    =======

    Copyright 2024 Gentoo Foundation, Inc; referenced text
    belongs to its owner(s).

    The contents of this document are licensed under the
    Creative Commons - Attribution / Share Alike license.

    https://creativecommons.org/licenses/by-sa/2.5
    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmY5A08ACgkQFMQkOaVy +9liSw//ewef+R0xs/aC6fX0mkDa6ZXmkYVPdApm5X3XZv1vV/McfnRbbO7ubpzn cV59x3dNmQgFZhTdNFlXkN8IgPDWA6afoX/vtWpVtVJ7dZPeQdvyE+iVst/6yog0 rHXoMRPGljN7K7s6pvL/XmkU/PQ4+NyTZejMt11d9xZV8MzLcsfrtt462/kb2nq0 QD25g5WI7McG2B6+6+jlZ63W1UV5VcspH0c/qV/p3T/YuBs1RyF7jQGaurEhE4SI d9kmdhahec5J0U4YwufhrlpunIbYD8FMqUO9L7uUAfbWofLb5imFHf9YUv1AGJSg sHUxkBeccx/2E1FcwyR7a2fFNlnGfhGNGFHNLONPrtb2dEfIFg2wCA8w2AvqA9Ha HP2T0wKsytiO/It3tCMM9LafhD9qTPijFDgMR+CxLyn29gg7lKQ0T49RLBJsjvLs HcWIY4JMJ2NQxya3yA3VcpdaYOS8gkaiHCRMrZt6Wnw6GvVGT8PTefOC2efVK3G9 8Kh05/s4r+CCxDzOr1AxlpiCfCjzt60DSgIDXrkXlEhyYPqgDiBwOvOTnM7+RC8G 2JweLF2IjVEFfSmuPui5f68pX7s7korqygnM7Qzl4SWO6I7V0hYke9VTzGI2FYn4 2GAZKdAKFg47qg4fuhXCGopgm+a91tUu9+uZnQXxOs+0g0AXDrU=
    =+Km/
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)