USN-5310-2
Dashboard / Vulnerabilities / USN-5310-2
USN-5310-2
Summary: glibc vulnerabilities
Details: USN-5310-1 fixed several vulnerabilities in GNU. This update provides the corresponding update for Ubuntu 16.04 ESM. Original advisory details: It was discovered that the GNU C library getcwd function incorrectly handled buffers. An attacker could use this issue to cause the GNU C Library to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2021-3999) It was discovered that the GNU C Library sunrpc module incorrectly handled buffer lengths. An attacker could possibly use this issue to cause the GNU C Library to crash, resulting in a denial of service. (CVE-2022-23218, CVE-2022-23219)
References: https://ubuntu.com/security/notices/USN-5310-2, https://ubuntu.com/security/CVE-2021-3999, https://ubuntu.com/security/CVE-2022-23218, https://ubuntu.com/security/CVE-2022-23219
Affected packages
Package
Name: glibc
Purl: pkg:deb/ubuntu/glibc?arch=source&distro=esm-infra%2Fxenial
Affected ranges
Type: ECOSYSTEM
Events:
