EulerOS 2.0 SP1 : glibc (EulerOS-SA-2017-1146)

This script is Copyright (C) 2017 Tenable Network Security, Inc.

Synopsis :

The remote EulerOS host is missing multiple security updates.

Description :

According to the versions of the glibc packages installed, the
EulerOS installation on the remote host is affected by the following
vulnerabilities :

- The nss_dns implementation of getnetbyname in GNU C
Library (aka glibc) before 2.21, when the DNS backend
in the Name Service Switch configuration is enabled,
allows remote attackers to cause a denial of service
(infinite loop) by sending a positive answer while a
network name is being process.(CVE-2014-9402)

- glibc contains a vulnerability that allows specially
crafted LD_LIBRARY_PATH values to manipulate the
heap/stack, causing them to alias, potentially
resulting in arbitrary code execution. Please note that
additional hardening changes have been made to glibc to
prevent manipulation of stack and heap memory but these
issues are not directly exploitable, as such they have
not been given a CVE. This affects glibc 2.25 and

Note that Tenable Network Security has extracted the preceding
description block directly from the EulerOS security advisory. Tenable
has attempted to automatically clean and format it as much as possible
without introducing additional issues.

See also :

Solution :

Update the affected glibc packages.

Risk factor :

High / CVSS Base Score : 7.8
CVSS Temporal Score : 6.1
Public Exploit Available : true

Family: Huawei Local Security Checks

Nessus Plugin ID: 102233 ()

Bugtraq ID: 71670

CVE ID: CVE-2014-9402

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now