{"id":21199,"date":"2022-03-02T20:08:54","date_gmt":"2022-03-02T17:08:54","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/166183\/USN-5310-1.txt"},"modified":"2022-03-06T11:45:18","modified_gmt":"2022-03-06T08:15:18","slug":"ubuntu-security-notice-usn-5310-1","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/ubuntu-security-notice-usn-5310-1\/","title":{"rendered":"Ubuntu Security Notice USN-5310-1"},"content":{"rendered":"<p dir=\"ltr\">==========================================================================<br \/>\nUbuntu Security Notice USN-5310-1<br \/>\nMarch 01, 2022<\/p>\n<p dir=\"ltr\">glibc vulnerabilities<br \/>\n==========================================================================<\/p>\n<p dir=\"ltr\">A security issue affects these releases of Ubuntu and its derivatives:<\/p>\n<p dir=\"ltr\">&#8211; Ubuntu 21.10<br \/>\n&#8211; Ubuntu 20.04 LTS<br \/>\n&#8211; Ubuntu 18.04 LTS<\/p>\n<p dir=\"ltr\">Summary:<\/p>\n<p dir=\"ltr\">Several security issues were fixed in GNU C Library.<\/p>\n<p dir=\"ltr\">Software Description:<br \/>\n&#8211; glibc: GNU C Library<\/p>\n<p dir=\"ltr\">Details:<\/p>\n<p dir=\"ltr\">Jan Engelhardt, Tavis Ormandy, and others discovered that the GNU C Library<br \/>\niconv feature incorrectly handled certain input sequences. An attacker<br \/>\ncould possibly use this issue to cause the GNU C Library to hang or crash,<br \/>\nresulting in a denial of service. This issue only affected Ubuntu 18.04 LTS<br \/>\nand Ubuntu 20.04 LTS. (CVE-2016-10228, CVE-2019-25013, CVE-2020-27618,<br \/>\nCVE-2020-29562, CVE-2021-3326)<\/p>\n<p dir=\"ltr\">Jason Royes and Samuel Dytrych discovered that the GNU C Library<br \/>\nincorrectly handled signed comparisons on ARMv7 targets. A remote attacker<br \/>\ncould use this issue to cause the GNU C Library to crash, resulting in a<br \/>\ndenial of service, or possibly execute arbitrary code. This issue only<br \/>\naffected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-6096)<\/p>\n<p dir=\"ltr\">It was discovered that the GNU C Library nscd daemon incorrectly handled<br \/>\ncertain netgroup lookups. An attacker could possibly use this issue to<br \/>\ncause the GNU C Library to crash, resulting in a denial of service. This<br \/>\nissue only affected Ubuntu 20.04 LTS. (CVE-2021-27645)<\/p>\n<p dir=\"ltr\">It was discovered that the GNU C Library wordexp function incorrectly<br \/>\nhandled certain patterns. An attacker could use this issue to cause the<br \/>\nGNU C Library to crash, resulting in a denial of service, or possibly<br \/>\nobtain sensitive information. This issue only affected Ubuntu 18.04 LTS and<br \/>\nUbuntu 20.04 LTS. (CVE-2021-35942)<\/p>\n<p dir=\"ltr\">It was discovered that the GNU C Library realpath function incorrectly<br \/>\nhandled return values. An attacker could possibly use this issue to obtain<br \/>\nsensitive information. This issue only affected Ubuntu 21.10.<br \/>\n(CVE-2021-3998)<\/p>\n<p dir=\"ltr\">It was discovered that the GNU C library getcwd function incorrectly<br \/>\nhandled buffers. An attacker could use this issue to cause the GNU C<br \/>\nLibrary to crash, resulting in a denial of service, or possibly execute<br \/>\narbitrary code. (CVE-2021-3999)<\/p>\n<p dir=\"ltr\">It was discovered that the GNU C Library sunrpc module incorrectly handled<br \/>\nbuffer lengths. An attacker could possibly use this issue to cause the GNU<br \/>\nC Library to crash, resulting in a denial of service. (CVE-2022-23218,<br \/>\nCVE-2022-23219)<\/p>\n<p dir=\"ltr\">Update instructions:<\/p>\n<p dir=\"ltr\">The problem can be corrected by updating your system to the following<br \/>\npackage versions:<\/p>\n<p dir=\"ltr\">Ubuntu 21.10:<br \/>\nlibc6 2.34-0ubuntu3.2<\/p>\n<p dir=\"ltr\">Ubuntu 20.04 LTS:<br \/>\nlibc6 2.31-0ubuntu9.7<\/p>\n<p dir=\"ltr\">Ubuntu 18.04 LTS:<br \/>\nlibc6 2.27-3ubuntu1.5<\/p>\n<p dir=\"ltr\">After a standard system update you need to reboot your computer to make<br \/>\nall the necessary changes.<\/p>\n<p dir=\"ltr\">References:<br \/>\nhttps:\/\/ubuntu.com\/security\/notices\/USN-5310-1<br \/>\nCVE-2016-10228, CVE-2019-25013, CVE-2020-27618, CVE-2020-29562,<br \/>\nCVE-2020-6096, CVE-2021-27645, CVE-2021-3326, CVE-2021-35942,<br \/>\nCVE-2021-3998, CVE-2021-3999, CVE-2022-23218, CVE-2022-23219<\/p>\n<p dir=\"ltr\">Package Information:<br \/>\nhttps:\/\/launchpad.net\/ubuntu\/+source\/glibc\/2.34-0ubuntu3.2<br \/>\nhttps:\/\/launchpad.net\/ubuntu\/+source\/glibc\/2.31-0ubuntu9.7<br \/>\nhttps:\/\/launchpad.net\/ubuntu\/+source\/glibc\/2.27-3ubuntu1.5<\/p>\n","protected":false},"excerpt":{"rendered":"<p>========================================================================== Ubuntu Security Notice USN-5310-1 March 01, 2022 glibc vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: &#8211; Ubuntu 21.10 &#8211; Ubuntu 20.04 LTS &#8211; Ubuntu 18.04 LTS Summary: Several security issues were fixed in GNU C Library. Software Description: &#8211; glibc: GNU C Library Details: Jan Engelhardt, Tavis Ormandy, &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-21199","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/21199","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=21199"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/21199\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=21199"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=21199"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=21199"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}