Family: Red Hat Local Security Checks --> Category: infos
RHSA-2004-383: glibc Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the glibc packages
Detailed Explanation for this Vulnerability Test
Updated glibc packages that fix a security flaw in the resolver as well as
dlclose handling are now available.
The GNU libc packages (known as glibc) contain the standard C libraries
used by applications.
A security audit of the glibc packages in Red Hat Enterprise Linux 2.1
found a flaw in the resolver library which was originally reported as
affecting versions of ISC BIND 4.9. This flaw also applied to glibc
versions before 2.3.2. A possible hacker who is able to send DNS responses
(perhaps by creating a malicious DNS server) could remotely exploit this
vulnerability to execute arbitrary code or cause a denial of service. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CVE-2002-0029 to this issue.
These updated packages also fix a dlclose function bug on certain shared
libraries, which caused program crashes.
All users of glibc should upgrade to these updated packages, which
resolve these issues.
Solution : http://rhn.redhat.com/errata/RHSA-2004-383.html
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.