glibc: CVE-2015-1472 CVE-2015-1473

Related Vulnerabilities: CVE-2015-1472   CVE-2015-1473   CVE-2012-3406   CVE-2014-4043   CVE-2014-9402   CVE-2013-7424  

Debian Bug report logs - #777197
glibc: CVE-2015-1472 CVE-2015-1473

version graph

Reported by: Moritz Muehlenhoff <jmm@inutil.org>

Date: Fri, 6 Feb 2015 07:51:02 UTC

Severity: grave

Tags: security

Fixed in versions glibc/2.19-15, eglibc/2.13-38+deb7u8

Done: Aurelien Jarno <aurel32@debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, GNU Libc Maintainers <debian-glibc@lists.debian.org>:
Bug#777197; Package glibc. (Fri, 06 Feb 2015 07:51:06 GMT) (full text, mbox, link).


Acknowledgement sent to Moritz Muehlenhoff <jmm@inutil.org>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, secure-testing-team@lists.alioth.debian.org, GNU Libc Maintainers <debian-glibc@lists.debian.org>. (Fri, 06 Feb 2015 07:51:06 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Moritz Muehlenhoff <jmm@inutil.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: glibc: CVE-2015-1472
Date: Fri, 06 Feb 2015 08:43:37 +0100
Package: glibc
Severity: grave
Tags: security
Justification: user security hole

Hi,
please see https://sourceware.org/bugzilla/show_bug.cgi?id=16618
The patch is here: https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=5bd80bfe9ca0d955bfbbc002781bc7b01b6bcb06

This was introduced by https://sourceware.org/git/?p=glibc.git;a=commitdiff;h=3f8cc204fdd0
(2.15). Since the patch was backported into wheezy, it is also
affected (while squeeze is not).

Cheers,
        Moritz



Information forwarded to debian-bugs-dist@lists.debian.org, GNU Libc Maintainers <debian-glibc@lists.debian.org>:
Bug#777197; Package glibc. (Fri, 06 Feb 2015 08:06:10 GMT) (full text, mbox, link).


Acknowledgement sent to Moritz Muehlenhoff <jmm@inutil.org>:
Extra info received and forwarded to list. Copy sent to GNU Libc Maintainers <debian-glibc@lists.debian.org>. (Fri, 06 Feb 2015 08:06:10 GMT) (full text, mbox, link).


Message #10 received at 777197@bugs.debian.org (full text, mbox, reply):

From: Moritz Muehlenhoff <jmm@inutil.org>
To: 777197@bugs.debian.org
Cc: control@bugs.debian.org
Subject: Re: glibc: CVE-2015-1472
Date: Fri, 6 Feb 2015 08:57:56 +0100
retitle: glibc: CVE-2015-1472 CVE-2015-1473
thanks

On Fri, Feb 06, 2015 at 08:43:37AM +0100, Moritz Muehlenhoff wrote:

> please see https://sourceware.org/bugzilla/show_bug.cgi?id=16618
> The patch is here: https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=5bd80bfe9ca0d955bfbbc002781bc7b01b6bcb06
> 
> This was introduced by https://sourceware.org/git/?p=glibc.git;a=commitdiff;h=3f8cc204fdd0
> (2.15). Since the patch was backported into wheezy, it is also
> affected (while squeeze is not).

This covers also CVE-2015-1473, see
http://www.openwall.com/lists/oss-security/2015/02/04/1

Cheers,
        Moritz




Changed Bug title to 'glibc: CVE-2015-1472 CVE-2015-1473' from 'glibc: CVE-2015-1472' Request was from Moritz Muehlenhoff <jmm@inutil.org> to control@bugs.debian.org. (Fri, 06 Feb 2015 08:15:04 GMT) (full text, mbox, link).


Information forwarded to debian-bugs-dist@lists.debian.org, GNU Libc Maintainers <debian-glibc@lists.debian.org>:
Bug#777197; Package glibc. (Sun, 08 Feb 2015 16:27:04 GMT) (full text, mbox, link).


Acknowledgement sent to Aurelien Jarno <aurelien@aurel32.net>:
Extra info received and forwarded to list. Copy sent to GNU Libc Maintainers <debian-glibc@lists.debian.org>. (Sun, 08 Feb 2015 16:27:04 GMT) (full text, mbox, link).


Message #17 received at 777197@bugs.debian.org (full text, mbox, reply):

From: Aurelien Jarno <aurelien@aurel32.net>
To: Moritz Muehlenhoff <jmm@inutil.org>, 777197@bugs.debian.org
Subject: Re: Bug#777197: glibc: CVE-2015-1472
Date: Sun, 8 Feb 2015 17:22:29 +0100
On 2015-02-06 08:43, Moritz Muehlenhoff wrote:
> Package: glibc
> Severity: grave
> Tags: security
> Justification: user security hole
> 
> Hi,
> please see https://sourceware.org/bugzilla/show_bug.cgi?id=16618
> The patch is here: https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=5bd80bfe9ca0d955bfbbc002781bc7b01b6bcb06
> 
> This was introduced by https://sourceware.org/git/?p=glibc.git;a=commitdiff;h=3f8cc204fdd0
> (2.15). Since the patch was backported into wheezy, it is also
> affected (while squeeze is not).

I have just done the upload to unstable, I'll prepare an upload for
wheezy with the other pending security fixes as soon as possible.

-- 
Aurelien Jarno                          GPG: 4096R/1DDD8C9B
aurelien@aurel32.net                 http://www.aurel32.net



Reply sent to Aurelien Jarno <aurel32@debian.org>:
You have taken responsibility. (Sun, 08 Feb 2015 16:45:09 GMT) (full text, mbox, link).


Notification sent to Moritz Muehlenhoff <jmm@inutil.org>:
Bug acknowledged by developer. (Sun, 08 Feb 2015 16:45:09 GMT) (full text, mbox, link).


Message #22 received at 777197-close@bugs.debian.org (full text, mbox, reply):

From: Aurelien Jarno <aurel32@debian.org>
To: 777197-close@bugs.debian.org
Subject: Bug#777197: fixed in glibc 2.19-15
Date: Sun, 08 Feb 2015 16:34:20 +0000
Source: glibc
Source-Version: 2.19-15

We believe that the bug you reported is fixed in the latest version of
glibc, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 777197@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Aurelien Jarno <aurel32@debian.org> (supplier of updated glibc package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Sun, 08 Feb 2015 15:54:37 +0100
Source: glibc
Binary: libc-bin libc-dev-bin glibc-doc glibc-source locales locales-all nscd multiarch-support libc6 libc6-dev libc6-dbg libc6-pic libc6-udeb libc6.1 libc6.1-dev libc6.1-dbg libc6.1-pic libc6.1-udeb libc0.3 libc0.3-dev libc0.3-dbg libc0.3-pic libc0.3-udeb libc0.1 libc0.1-dev libc0.1-dbg libc0.1-pic libc0.1-udeb libc6-i386 libc6-dev-i386 libc6-sparc libc6-dev-sparc libc6-sparc64 libc6-dev-sparc64 libc6-s390 libc6-dev-s390 libc6-amd64 libc6-dev-amd64 libc6-powerpc libc6-dev-powerpc libc6-ppc64 libc6-dev-ppc64 libc6-mips32 libc6-dev-mips32 libc6-mipsn32 libc6-dev-mipsn32 libc6-mips64 libc6-dev-mips64 libc0.1-i386 libc0.1-dev-i386 libc6-x32 libc6-dev-x32 libc6-i686 libc6-xen libc0.1-i686 libc0.3-i686 libc0.3-xen libc6.1-alphaev67 libc6-loongson2f libnss-dns-udeb libnss-files-udeb
Architecture: source all amd64
Version: 2.19-15
Distribution: unstable
Urgency: medium
Maintainer: GNU Libc Maintainers <debian-glibc@lists.debian.org>
Changed-By: Aurelien Jarno <aurel32@debian.org>
Description:
 glibc-doc  - GNU C Library: Documentation
 glibc-source - GNU C Library: sources
 libc-bin   - GNU C Library: Binaries
 libc-dev-bin - GNU C Library: Development binaries
 libc0.1    - GNU C Library: Shared libraries
 libc0.1-dbg - GNU C Library: detached debugging symbols
 libc0.1-dev - GNU C Library: Development Libraries and Header Files
 libc0.1-dev-i386 - GNU C Library: 32bit development libraries for AMD64
 libc0.1-i386 - GNU C Library: 32bit shared libraries for AMD64
 libc0.1-i686 - GNU C Library: Shared libraries [i686 optimized]
 libc0.1-pic - GNU C Library: PIC archive library
 libc0.1-udeb - GNU C Library: Shared libraries - udeb (udeb)
 libc0.3    - GNU C Library: Shared libraries
 libc0.3-dbg - GNU C Library: detached debugging symbols
 libc0.3-dev - GNU C Library: Development Libraries and Header Files
 libc0.3-i686 - GNU C Library: Shared libraries [i686 optimized]
 libc0.3-pic - GNU C Library: PIC archive library
 libc0.3-udeb - GNU C Library: Shared libraries - udeb (udeb)
 libc0.3-xen - GNU C Library: Shared libraries [Xen version]
 libc6      - GNU C Library: Shared libraries
 libc6-amd64 - GNU C Library: 64bit Shared libraries for AMD64
 libc6-dbg  - GNU C Library: detached debugging symbols
 libc6-dev  - GNU C Library: Development Libraries and Header Files
 libc6-dev-amd64 - GNU C Library: 64bit Development Libraries for AMD64
 libc6-dev-i386 - GNU C Library: 32-bit development libraries for AMD64
 libc6-dev-mips32 - GNU C Library: o32 Development Libraries for MIPS
 libc6-dev-mips64 - GNU C Library: 64bit Development Libraries for MIPS64
 libc6-dev-mipsn32 - GNU C Library: n32 Development Libraries for MIPS64
 libc6-dev-powerpc - GNU C Library: 32bit powerpc development libraries for ppc64
 libc6-dev-ppc64 - GNU C Library: 64bit Development Libraries for PowerPC64
 libc6-dev-s390 - GNU C Library: 32bit Development Libraries for IBM zSeries
 libc6-dev-sparc - GNU C Library: 32bit Development Libraries for SPARC
 libc6-dev-sparc64 - GNU C Library: 64bit Development Libraries for UltraSPARC
 libc6-dev-x32 - GNU C Library: X32 ABI Development Libraries for AMD64
 libc6-i386 - GNU C Library: 32-bit shared libraries for AMD64
 libc6-i686 - GNU C Library: Shared libraries [i686 optimized]
 libc6-loongson2f - GNU C Library: Shared libraries (Loongson 2F optimized)
 libc6-mips32 - GNU C Library: o32 Shared libraries for MIPS
 libc6-mips64 - GNU C Library: 64bit Shared libraries for MIPS64
 libc6-mipsn32 - GNU C Library: n32 Shared libraries for MIPS64
 libc6-pic  - GNU C Library: PIC archive library
 libc6-powerpc - GNU C Library: 32bit powerpc shared libraries for ppc64
 libc6-ppc64 - GNU C Library: 64bit Shared libraries for PowerPC64
 libc6-s390 - GNU C Library: 32bit Shared libraries for IBM zSeries
 libc6-sparc - GNU C Library: 32bit Shared libraries for SPARC
 libc6-sparc64 - GNU C Library: 64bit Shared libraries for UltraSPARC
 libc6-udeb - GNU C Library: Shared libraries - udeb (udeb)
 libc6-x32  - GNU C Library: X32 ABI Shared libraries for AMD64
 libc6-xen  - GNU C Library: Shared libraries [Xen version]
 libc6.1    - GNU C Library: Shared libraries
 libc6.1-alphaev67 - GNU C Library: Shared libraries (EV67 optimized)
 libc6.1-dbg - GNU C Library: detached debugging symbols
 libc6.1-dev - GNU C Library: Development Libraries and Header Files
 libc6.1-pic - GNU C Library: PIC archive library
 libc6.1-udeb - GNU C Library: Shared libraries - udeb (udeb)
 libnss-dns-udeb - GNU C Library: NSS helper for DNS - udeb (udeb)
 libnss-files-udeb - GNU C Library: NSS helper for files - udeb (udeb)
 locales    - GNU C Library: National Language (locale) data [support]
 locales-all - GNU C Library: Precompiled locale data
 multiarch-support - Transitional package to ensure multiarch compatibility
 nscd       - GNU C Library: Name Service Cache Daemon
Closes: 777197
Changes:
 glibc (2.19-15) unstable; urgency=medium
 .
   [ Aurelien Jarno ]
   * debian/patches/any/cvs-wscanf.diff: new patch from upstream to fix a
     heap buffer overflow in wscanf (CVE-2015-1472, CVE-2015-1473). Closes:
     #777197.
Checksums-Sha1:
 c155f97e2cc122bb82819645e04590271961d247 8208 glibc_2.19-15.dsc
 8a51bc9c209b3adef5271e18d2b4a93867f3d622 1039604 glibc_2.19-15.debian.tar.xz
 d2db4cfa2c9085610fa7c8673f07dbe7cb53dd12 2264696 glibc-doc_2.19-15_all.deb
 c96a090446f59cf46f2596bc549246f23d9bd6f5 13938480 glibc-source_2.19-15_all.deb
 9420dda9c185d1d0d6abd14d56958a5dd8f22420 3937166 locales_2.19-15_all.deb
Checksums-Sha256:
 41d3128ebdafd04dbe6c1b7ffbe62c1aec536f63e7874cfea225c6e4d6ec056c 8208 glibc_2.19-15.dsc
 96d9de5b3ae0ce86cb5711904de4ef8f09482a5d591bbf4da12d5d2cbc721204 1039604 glibc_2.19-15.debian.tar.xz
 a24309510c88c613c3b42cf8c5b3c333c1445a16ce960a542ceb0e562dfe97e0 2264696 glibc-doc_2.19-15_all.deb
 408f4eb411004152eb0a7bd1ba6799a72f69aafdf7da938c2f1e91824af794da 13938480 glibc-source_2.19-15_all.deb
 8e34d7108c8ddf744a8da6a3a907a6bb76889ca685b8d239405c3fda04ac11ec 3937166 locales_2.19-15_all.deb
Files:
 5520aa6db9b92208bf6c2962b151c684 8208 libs required glibc_2.19-15.dsc
 bfa8b23dcc421e949661ea88087848dc 1039604 libs required glibc_2.19-15.debian.tar.xz
 9082d56a187224dde75509608cca1ba3 2264696 doc optional glibc-doc_2.19-15_all.deb
 239dd67638485b5136e48d2f358f6e48 13938480 devel optional glibc-source_2.19-15_all.deb
 84652f43c8b8b3b41e8cd0b27a2fc238 3937166 localization standard locales_2.19-15_all.deb
Package-Type: udeb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBAgAGBQJU14zzAAoJELqceAYd3YybJ3kQAKK9LtlJ3MDzDSOMu7pcwasz
401TzpYDkkhoZS4v4ORE0NemOqfZMH4jLIAPuYnYebZZtE+zieO3zog0bw8Y1vCG
uRMx/bCcIsWZ1DmK5+W8yLIC9QSPMIuumeZmxMiosmuEzYTUEEYS6HFhWn87Lh54
W4jHHeVBROovhdd+8J8yHfS+5ttLsNtlQxgQjKQfkpuLchTlxQ6aU8QJ7lVI8zfW
K3c8kEwuizPl8ATXAvfPUr9OiHSXo7L8Kza2+8hRG48ZdNa40E+oFVqDFgx9h4BL
23Ndk2wiR4Itgk7s7GeQedj+aOrfurEQfweyVeKJXQskonhqxtgm2hwpyaBjBVZG
bnDPi8qC+4BMawoDOdHppKeNf/1ldD66i3UOSwQVWeUCJYJtmwmjIJ+xfgEeG0Fk
MTNHaj7IIRK1QfX4fi4zpBTQD96jcafqY8s+ho5nSXWKQFHSV8WzkknWa/U/c6ub
y8w/YyYtrLi3i+nLju9uFHe9ijqW90KXaHDMgcKdEUUe6Up4kj1cBE2epsrIkfFw
H7xVZo41QW6WyNC5SFaKkSveoXJr3+LUlfWngme3tmC4G6ItA3VuTsZUA1CURa2x
k2K5r6ic6wShFtYTeLlQYRG+DAbt60fbwK5LYjiiPgfT6G1u3jgmnIBL3vVXHJ8e
uSejSz/oT4VG5Uvsu8wb
=MKfO
-----END PGP SIGNATURE-----




Reply sent to Aurelien Jarno <aurel32@debian.org>:
You have taken responsibility. (Sat, 28 Feb 2015 18:06:38 GMT) (full text, mbox, link).


Notification sent to Moritz Muehlenhoff <jmm@inutil.org>:
Bug acknowledged by developer. (Sat, 28 Feb 2015 18:06:38 GMT) (full text, mbox, link).


Message #27 received at 777197-close@bugs.debian.org (full text, mbox, reply):

From: Aurelien Jarno <aurel32@debian.org>
To: 777197-close@bugs.debian.org
Subject: Bug#777197: fixed in eglibc 2.13-38+deb7u8
Date: Sat, 28 Feb 2015 18:02:32 +0000
Source: eglibc
Source-Version: 2.13-38+deb7u8

We believe that the bug you reported is fixed in the latest version of
eglibc, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 777197@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Aurelien Jarno <aurel32@debian.org> (supplier of updated eglibc package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Sun, 22 Feb 2015 09:49:50 +0100
Source: eglibc
Binary: libc-bin libc-dev-bin glibc-doc eglibc-source locales locales-all nscd multiarch-support libc6 libc6-dev libc6-dbg libc6-prof libc6-pic libc6-udeb libc6.1 libc6.1-dev libc6.1-dbg libc6.1-prof libc6.1-pic libc6.1-udeb libc0.3 libc0.3-dev libc0.3-dbg libc0.3-prof libc0.3-pic libc0.3-udeb libc0.1 libc0.1-dev libc0.1-dbg libc0.1-prof libc0.1-pic libc0.1-udeb libc6-i386 libc6-dev-i386 libc6-sparc64 libc6-dev-sparc64 libc6-s390 libc6-dev-s390 libc6-s390x libc6-dev-s390x libc6-amd64 libc6-dev-amd64 libc6-powerpc libc6-dev-powerpc libc6-ppc64 libc6-dev-ppc64 libc6-mipsn32 libc6-dev-mipsn32 libc6-mips64 libc6-dev-mips64 libc0.1-i386 libc0.1-dev-i386 libc6-i686 libc6-xen libc0.1-i686 libc0.3-i686 libc0.3-xen libc6.1-alphaev67 libc6-loongson2f libnss-dns-udeb libnss-files-udeb
Architecture: source all
Version: 2.13-38+deb7u8
Distribution: wheezy-security
Urgency: medium
Maintainer: GNU Libc Maintainers <debian-glibc@lists.debian.org>
Changed-By: Aurelien Jarno <aurel32@debian.org>
Description: 
 eglibc-source - Embedded GNU C Library: sources
 glibc-doc  - Embedded GNU C Library: Documentation
 libc-bin   - Embedded GNU C Library: Binaries
 libc-dev-bin - Embedded GNU C Library: Development binaries
 libc0.1    - Embedded GNU C Library: Shared libraries
 libc0.1-dbg - Embedded GNU C Library: detached debugging symbols
 libc0.1-dev - Embedded GNU C Library: Development Libraries and Header Files
 libc0.1-dev-i386 - Embedded GNU C Library: 32bit development libraries for AMD64
 libc0.1-i386 - Embedded GNU C Library: 32bit shared libraries for AMD64
 libc0.1-i686 - Embedded GNU C Library: Shared libraries [i686 optimized]
 libc0.1-pic - Embedded GNU C Library: PIC archive library
 libc0.1-prof - Embedded GNU C Library: Profiling Libraries
 libc0.1-udeb - Embedded GNU C Library: Shared libraries - udeb (udeb)
 libc0.3    - Embedded GNU C Library: Shared libraries
 libc0.3-dbg - Embedded GNU C Library: detached debugging symbols
 libc0.3-dev - Embedded GNU C Library: Development Libraries and Header Files
 libc0.3-i686 - Embedded GNU C Library: Shared libraries [i686 optimized]
 libc0.3-pic - Embedded GNU C Library: PIC archive library
 libc0.3-prof - Embedded GNU C Library: Profiling Libraries
 libc0.3-udeb - Embedded GNU C Library: Shared libraries - udeb (udeb)
 libc0.3-xen - Embedded GNU C Library: Shared libraries [Xen version]
 libc6      - Embedded GNU C Library: Shared libraries
 libc6-amd64 - Embedded GNU C Library: 64bit Shared libraries for AMD64
 libc6-dbg  - Embedded GNU C Library: detached debugging symbols
 libc6-dev  - Embedded GNU C Library: Development Libraries and Header Files
 libc6-dev-amd64 - Embedded GNU C Library: 64bit Development Libraries for AMD64
 libc6-dev-i386 - Embedded GNU C Library: 32-bit development libraries for AMD64
 libc6-dev-mips64 - Embedded GNU C Library: 64bit Development Libraries for MIPS64
 libc6-dev-mipsn32 - Embedded GNU C Library: n32 Development Libraries for MIPS64
 libc6-dev-powerpc - Embedded GNU C Library: 32bit powerpc development libraries for p
 libc6-dev-ppc64 - Embedded GNU C Library: 64bit Development Libraries for PowerPC64
 libc6-dev-s390 - Embedded GNU C Library: 32bit Development Libraries for IBM zSeri
 libc6-dev-s390x - Embedded GNU C Library: 64bit Development Libraries for IBM zSeri
 libc6-dev-sparc64 - Embedded GNU C Library: 64bit Development Libraries for UltraSPAR
 libc6-i386 - Embedded GNU C Library: 32-bit shared libraries for AMD64
 libc6-i686 - Embedded GNU C Library: Shared libraries [i686 optimized]
 libc6-loongson2f - Embedded GNU C Library: Shared libraries (Loongson 2F optimized)
 libc6-mips64 - Embedded GNU C Library: 64bit Shared libraries for MIPS64
 libc6-mipsn32 - Embedded GNU C Library: n32 Shared libraries for MIPS64
 libc6-pic  - Embedded GNU C Library: PIC archive library
 libc6-powerpc - Embedded GNU C Library: 32bit powerpc shared libraries for ppc64
 libc6-ppc64 - Embedded GNU C Library: 64bit Shared libraries for PowerPC64
 libc6-prof - Embedded GNU C Library: Profiling Libraries
 libc6-s390 - Embedded GNU C Library: 32bit Shared libraries for IBM zSeries
 libc6-s390x - Embedded GNU C Library: 64bit Shared libraries for IBM zSeries
 libc6-sparc64 - Embedded GNU C Library: 64bit Shared libraries for UltraSPARC
 libc6-udeb - Embedded GNU C Library: Shared libraries - udeb (udeb)
 libc6-xen  - Embedded GNU C Library: Shared libraries [Xen version]
 libc6.1    - Embedded GNU C Library: Shared libraries
 libc6.1-alphaev67 - Embedded GNU C Library: Shared libraries (EV67 optimized)
 libc6.1-dbg - Embedded GNU C Library: detached debugging symbols
 libc6.1-dev - Embedded GNU C Library: Development Libraries and Header Files
 libc6.1-pic - Embedded GNU C Library: PIC archive library
 libc6.1-prof - Embedded GNU C Library: Profiling Libraries
 libc6.1-udeb - Embedded GNU C Library: Shared libraries - udeb (udeb)
 libnss-dns-udeb - Embedded GNU C Library: NSS helper for DNS - udeb (udeb)
 libnss-files-udeb - Embedded GNU C Library: NSS helper for files - udeb (udeb)
 locales    - Embedded GNU C Library: National Language (locale) data [support]
 locales-all - Embedded GNU C Library: Precompiled locale data
 multiarch-support - Transitional package to ensure multiarch compatibility
 nscd       - Embedded GNU C Library: Name Service Cache Daemon
Closes: 681888 751774 775572 777197
Changes: 
 eglibc (2.13-38+deb7u8) wheezy-security; urgency=medium
 .
   * debian/patches/any/cvs-wscanf.diff: new patch from upstream to fix a
     heap buffer overflow in wscanf (CVE-2015-1472, CVE-2015-1473). Closes:
     #777197.
   * debian/patches/any/cvs-vfprintf.diff: new patch from ustream to fix a
     stack overflow in vfprintf (CVE-2012-3406). Closes: #681888.
   * debian/patches/any/cvs-posix_spawn_file_actions_addopen.diff: new patch
     from upstream to fix a vulnerability in posix_spawn_file_actions_addopen
     (CVE-2014-4043). Closes: #751774.
   * debian/patches/any/cvs-getnetbyname.diff: new patch from upstream to fix
     an infinite loop in getnetbyname (CVE-2014-9402). Closes: #775572.
   * debian/patches/any/cvs-getaddrinfo-idn.diff: new patch from upstream to
     fix a invalid-free when using getaddrinfo with IDN (CVE-2013-7424).
Checksums-Sha1: 
 3f6024c33cbbc28cfb7408cf1bd71158dbe65b25 5387 eglibc_2.13-38+deb7u8.dsc
 ad16463f72e7a6ad264e8b1f55d715aa6c150ee1 2025161 eglibc_2.13-38+deb7u8.diff.gz
 6bf967beca00993870856d92ab374a08efe1f9d5 1898264 glibc-doc_2.13-38+deb7u8_all.deb
 a992fd0b8381153cd9a599875ac9fe87372b1e70 13418902 eglibc-source_2.13-38+deb7u8_all.deb
 6c04e6f5231c8792096221e0b7b3f4735534fa84 5708190 locales_2.13-38+deb7u8_all.deb
Checksums-Sha256: 
 761e09d1e83fd7ff5f9b584ff3d4433f974ed56e5c9f58a180ed348d8a67ea3f 5387 eglibc_2.13-38+deb7u8.dsc
 752897b2dbc581bbea10077e441c93bee1d6824c055b4ddfe3ca1809c4d2ca31 2025161 eglibc_2.13-38+deb7u8.diff.gz
 3823cab9e753bea3257eafce36579c9a9a7e4442ae3e7ebe40d6e48a1890e24d 1898264 glibc-doc_2.13-38+deb7u8_all.deb
 2d271f80e9270847df12f95e4d9b89682c959ce0577fdefc74b4397f84b2ced9 13418902 eglibc-source_2.13-38+deb7u8_all.deb
 fbdec82cc2790947d1c1ddefb9086a386de2ce632afcc03161029a1953836e93 5708190 locales_2.13-38+deb7u8_all.deb
Files: 
 6a68d1b168b660d1e8d91757ab680dc4 5387 libs required eglibc_2.13-38+deb7u8.dsc
 027e0ddf239ee6e61957392600a14604 2025161 libs required eglibc_2.13-38+deb7u8.diff.gz
 05b799c7293911693044cb7cb76114c8 1898264 doc optional glibc-doc_2.13-38+deb7u8_all.deb
 865c319d96eb093222f1de12701058b2 13418902 devel optional eglibc-source_2.13-38+deb7u8_all.deb
 7b8e6d7c91f624195b951ba7d10908af 5708190 localization standard locales_2.13-38+deb7u8_all.deb
Package-Type: udeb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQIcBAEBAgAGBQJU6aGJAAoJELqceAYd3YybtXsQAJivjjk+19Db+uZYp7Tf99t4
aWf9k7SMjt7jbsg+zl39p4T/cGxGnz0dzDmqmKxTwm8Wn2viNV9x8xxJCzTcv1gZ
9llEj3ucD2AsYxQJdRoqYvuRnMkQFxfVx04jrZbZgpwEfm3IbmWfQOpYBBVa1ilu
OOlHm2s54K3tQvAF7htZsMuHNwmofgMv9e7SKQlg2lg31yXTwGakAnkifW0Kdvgt
emJ+mMvUIfsCOr/ZMYZxzeFc3+W9qng1L4/0HE5DT2TLMUCfLQHjhZwYUf8kKhgx
i3+aJxmWlPfUhXd8s/k5xCRphHmH8aDrV2StHguaZnViBqobNPRgjhNSTJvQPT+m
O95pivwJZOa79Wq15CX/0k6gwWfQOr1ADcoLxzhkm3zAMlOxFSrJ1GCL1acon9Hj
5aht/D0qpho3YPCq6e1+DFevj48egRFP4v5QccpyVESWAB+4q6oRox6r9poyVUF1
CBQXNN6ENbago4DGZdTP015ysIsOdlyaV7M160VGxfsihkESPWAnoB9OG4vA7hDA
YuJC1J9/DKxx2p0figp50H+R2zNs1JBAO6YRcxkin1bjpS2cf5vYkvO8zXsOvVTA
pzZAcDCGFPILxdbBSKsrqAndInK/QneZjYzMgfvWrT/csduVz+lnM+yw0NtxKV/w
jQW1UI4FM3WnS5c0n2F7
=KGAX
-----END PGP SIGNATURE-----




Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Sun, 29 Mar 2015 07:30:08 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 14:55:56 2019; Machine Name: beach

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.