MGASA-2018-0096
Dashboard / Vulnerabilities / MGASA-2018-0096
MGASA-2018-0096
Summary: Updated glibc packages fix security vulnerabilities
Details: Updated glibc packages fix security vulnerabilities: An issue in the code handling RPATHs was fixed that could have been exploited by an attacker to execute code loaded from arbitrary libraries (CVE-2017-16997). A privilege escalation bug in the realpath() function when the getcwd() system call doesn't return a valid absolute pathname (CVE-2018-1000001). Also, support for the C.UTF-8 locale has been added in the locales package.
References: https://advisories.mageia.org/MGASA-2018-0096.html, https://bugs.mageia.org/show_bug.cgi?id=22375, https://lists.opensuse.org/opensuse-updates/2018-01/msg00033.html
Affected packages
Package
Name: glibc
Purl: pkg:rpm/mageia/glibc?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
