EulerOS 2.0 SP1 : glibc (EulerOS-SA-2017-1146)

This script is Copyright (C) 2017 Tenable Network Security, Inc.


Synopsis :

The remote EulerOS host is missing multiple security updates.

Description :

According to the versions of the glibc packages installed, the
EulerOS installation on the remote host is affected by the following
vulnerabilities :

- The nss_dns implementation of getnetbyname in GNU C
Library (aka glibc) before 2.21, when the DNS backend
in the Name Service Switch configuration is enabled,
allows remote attackers to cause a denial of service
(infinite loop) by sending a positive answer while a
network name is being process.(CVE-2014-9402)

- glibc contains a vulnerability that allows specially
crafted LD_LIBRARY_PATH values to manipulate the
heap/stack, causing them to alias, potentially
resulting in arbitrary code execution. Please note that
additional hardening changes have been made to glibc to
prevent manipulation of stack and heap memory but these
issues are not directly exploitable, as such they have
not been given a CVE. This affects glibc 2.25 and
earlier.(CVE-2017-1000366)

Note that Tenable Network Security has extracted the preceding
description block directly from the EulerOS security advisory. Tenable
has attempted to automatically clean and format it as much as possible
without introducing additional issues.

See also :

http://www.nessus.org/u?5ea363ed

Solution :

Update the affected glibc packages.

Risk factor :

High / CVSS Base Score : 7.8
(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)
CVSS Temporal Score : 6.1
(CVSS2#E:POC/RL:OF/RC:ND)
Public Exploit Available : true

Family: Huawei Local Security Checks

Nessus Plugin ID: 102233 ()

Bugtraq ID: 71670

CVE ID: CVE-2014-9402
CVE-2017-1000366

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now