Family: Fedora Local Security Checks --> Category: infos
Fedora Core 1 2003-002: glibc Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the glibc package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory FEDORA-2003-002 (glibc).
The glibc package contains standard libraries which are used by
multiple programs on the system. In order to save disk space and
memory, as well as to make upgrading easier, common system code is
kept in one place and shared between programs. This particular package
contains the most important sets of shared libraries: the standard C
library and the standard math library. Without these two libraries, a
Linux system will not function.
Herbert Xu reported that various applications can accept spoofed messages
sent on the kernel netlink interface by other users on the local machine.
This could lead to a local denial of service attack. The glibc function
getifaddrs uses netlink and could therefore be vulnerable to this issue.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CVE-2003-0859 to this issue.
In addition to this this update fixes a couple of bugs.
Solution : http://www.fedoranews.org/updates/FEDORA-2003-002.shtml
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.