Amazon Linux AMI : glibc (ALAS-2015-495)
Medium Nessus Plugin ID 82044
SynopsisThe remote Amazon Linux AMI host is missing a security update.
DescriptionAn out-of-bounds read flaw was found in the way glibc's iconv() function converted certain encoded data to UTF-8. An attacker able to make an application call the iconv() function with a specially crafted argument could use this flaw to crash that application.
It was found that the files back end of Name Service Switch (NSS) did not isolate iteration over an entire database from key-based look-up API calls. An application performing look-ups on a database while iterating over it could enter an infinite loop, leading to a denial of service. (CVE-2014-8121)
SolutionRun 'yum update glibc' to update your system.