This script is Copyright (C) 2017 Tenable Network Security, Inc.
The remote EulerOS host is missing multiple security updates.
According to the versions of the glibc packages installed, the
EulerOS installation on the remote host is affected by the following
- The nss_dns implementation of getnetbyname in GNU C
Library (aka glibc) before 2.21, when the DNS backend
in the Name Service Switch configuration is enabled,
allows remote attackers to cause a denial of service
(infinite loop) by sending a positive answer while a
network name is being process.(CVE-2014-9402)
- glibc contains a vulnerability that allows specially
crafted LD_LIBRARY_PATH values to manipulate the
heap/stack, causing them to alias, potentially
resulting in arbitrary code execution. Please note that
additional hardening changes have been made to glibc to
prevent manipulation of stack and heap memory but these
issues are not directly exploitable, as such they have
not been given a CVE. This affects glibc 2.25 and
Note that Tenable Network Security has extracted the preceding
description block directly from the EulerOS security advisory. Tenable
has attempted to automatically clean and format it as much as possible
without introducing additional issues.
See also :
Update the affected glibc packages.
Risk factor :
High / CVSS Base Score : 7.8
CVSS Temporal Score : 6.1
Public Exploit Available : true