DSA-103-1 glibc -- buffer overflow

Related Vulnerabilities: CVE-2001-0886  

A buffer overflow has been found in the globbing code for glibc. This is the code which is used to glob patterns for filenames and is commonly used in applications like shells and FTP servers. This has been fixed in version 2.1.3-20 and we recommend that you upgrade your libc package immediately.

Debian Security Advisory

DSA-103-1 glibc -- buffer overflow

Date Reported:
13 Jan 2002
Affected Packages:
glibc
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2001-0886.
More information:

A buffer overflow has been found in the globbing code for glibc. This is the code which is used to glob patterns for filenames and is commonly used in applications like shells and FTP servers.

This has been fixed in version 2.1.3-20 and we recommend that you upgrade your libc package immediately.

Fixed in:

Debian GNU/Linux 2.2 (potato)

Source:
http://security.debian.org/dists/stable/updates/main/source/glibc_2.1.3-20.diff.gz
http://security.debian.org/dists/stable/updates/main/source/glibc_2.1.3-20.dsc
http://security.debian.org/dists/stable/updates/main/source/glibc_2.1.3.orig.tar.gz
Architecture-independent component:
http://security.debian.org/dists/stable/updates/main/binary-all/glibc-doc_2.1.3-20_all.deb
http://security.debian.org/dists/stable/updates/main/binary-all/i18ndata_2.1.3-20_all.deb
Alpha:
http://security.debian.org/dists/stable/updates/main/binary-alpha/libc6.1-dbg_2.1.3-20_alpha.deb
http://security.debian.org/dists/stable/updates/main/binary-alpha/libc6.1-dev_2.1.3-20_alpha.deb
http://security.debian.org/dists/stable/updates/main/binary-alpha/libc6.1-pic_2.1.3-20_alpha.deb
http://security.debian.org/dists/stable/updates/main/binary-alpha/libc6.1-prof_2.1.3-20_alpha.deb
http://security.debian.org/dists/stable/updates/main/binary-alpha/libc6.1_2.1.3-20_alpha.deb
http://security.debian.org/dists/stable/updates/main/binary-alpha/libnss1-compat_2.1.3-20_alpha.deb
http://security.debian.org/dists/stable/updates/main/binary-alpha/locales_2.1.3-20_alpha.deb
http://security.debian.org/dists/stable/updates/main/binary-alpha/nscd_2.1.3-20_alpha.deb
ARM:
http://security.debian.org/dists/stable/updates/main/binary-arm/libc6-dbg_2.1.3-20_arm.deb
http://security.debian.org/dists/stable/updates/main/binary-arm/libc6-dev_2.1.3-20_arm.deb
http://security.debian.org/dists/stable/updates/main/binary-arm/libc6-pic_2.1.3-20_arm.deb
http://security.debian.org/dists/stable/updates/main/binary-arm/libc6-prof_2.1.3-20_arm.deb
http://security.debian.org/dists/stable/updates/main/binary-arm/libc6_2.1.3-20_arm.deb
http://security.debian.org/dists/stable/updates/main/binary-arm/locales_2.1.3-20_arm.deb
http://security.debian.org/dists/stable/updates/main/binary-arm/nscd_2.1.3-20_arm.deb
Intel IA-32:
http://security.debian.org/dists/stable/updates/main/binary-i386/libc6-dbg_2.1.3-20_i386.deb
http://security.debian.org/dists/stable/updates/main/binary-i386/libc6-dev_2.1.3-20_i386.deb
http://security.debian.org/dists/stable/updates/main/binary-i386/libc6-pic_2.1.3-20_i386.deb
http://security.debian.org/dists/stable/updates/main/binary-i386/libc6-prof_2.1.3-20_i386.deb
http://security.debian.org/dists/stable/updates/main/binary-i386/libc6_2.1.3-20_i386.deb
http://security.debian.org/dists/stable/updates/main/binary-i386/libnss1-compat_2.1.3-20_i386.deb
http://security.debian.org/dists/stable/updates/main/binary-i386/locales_2.1.3-20_i386.deb
http://security.debian.org/dists/stable/updates/main/binary-i386/nscd_2.1.3-20_i386.deb
Motorola 680x0:
http://security.debian.org/dists/stable/updates/main/binary-m68k/libc6-dbg_2.1.3-20_m68k.deb
http://security.debian.org/dists/stable/updates/main/binary-m68k/libc6-dev_2.1.3-20_m68k.deb
http://security.debian.org/dists/stable/updates/main/binary-m68k/libc6-pic_2.1.3-20_m68k.deb
http://security.debian.org/dists/stable/updates/main/binary-m68k/libc6-prof_2.1.3-20_m68k.deb
http://security.debian.org/dists/stable/updates/main/binary-m68k/libc6_2.1.3-20_m68k.deb
http://security.debian.org/dists/stable/updates/main/binary-m68k/libnss1-compat_2.1.3-20_m68k.deb
http://security.debian.org/dists/stable/updates/main/binary-m68k/locales_2.1.3-20_m68k.deb
http://security.debian.org/dists/stable/updates/main/binary-m68k/nscd_2.1.3-20_m68k.deb
PowerPC:
http://security.debian.org/dists/stable/updates/main/binary-powerpc/libc6-dbg_2.1.3-20_powerpc.deb
http://security.debian.org/dists/stable/updates/main/binary-powerpc/libc6-dev_2.1.3-20_powerpc.deb
http://security.debian.org/dists/stable/updates/main/binary-powerpc/libc6-pic_2.1.3-20_powerpc.deb
http://security.debian.org/dists/stable/updates/main/binary-powerpc/libc6-prof_2.1.3-20_powerpc.deb
http://security.debian.org/dists/stable/updates/main/binary-powerpc/libc6_2.1.3-20_powerpc.deb
http://security.debian.org/dists/stable/updates/main/binary-powerpc/locales_2.1.3-20_powerpc.deb
http://security.debian.org/dists/stable/updates/main/binary-powerpc/nscd_2.1.3-20_powerpc.deb
Sun Sparc:
http://security.debian.org/dists/stable/updates/main/binary-sparc/libc6-dbg_2.1.3-20_sparc.deb
http://security.debian.org/dists/stable/updates/main/binary-sparc/libc6-dev_2.1.3-20_sparc.deb
http://security.debian.org/dists/stable/updates/main/binary-sparc/libc6-pic_2.1.3-20_sparc.deb
http://security.debian.org/dists/stable/updates/main/binary-sparc/libc6-prof_2.1.3-20_sparc.deb
http://security.debian.org/dists/stable/updates/main/binary-sparc/libc6_2.1.3-20_sparc.deb
http://security.debian.org/dists/stable/updates/main/binary-sparc/locales_2.1.3-20_sparc.deb
http://security.debian.org/dists/stable/updates/main/binary-sparc/nscd_2.1.3-20_sparc.deb

MD5 checksums of the listed files are available in the original advisory.