Details
Tavis Ormandy discovered multiple flaws in the GNU C Library’s handling
of the LD_AUDIT environment variable when running a privileged binary. A
local attacker could exploit this to gain root privileges. (CVE-2010-3847,
CVE-2010-3856)
Tavis Ormandy discovered multiple flaws in the GNU C Library’s handling
of the LD_AUDIT environment variable when running a privileged binary. A
local attacker could exploit this to gain root privileges. (CVE-2010-3847,
CVE-2010-3856)
Update instructions
In general, a standard system update will make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
Ubuntu Release | Package Version | ||
---|---|---|---|
9.10 karmic | libc6 – 2.10.1-0ubuntu18 | ||
9.04 jaunty | libc6 – 2.9-4ubuntu6.3 | ||
8.04 hardy | libc6 – 2.7-10ubuntu7 | ||
10.10 maverick | libc6 – 2.12.1-0ubuntu8 | ||
10.04 lucid | libc6 – 2.11.1-0ubuntu7.5 |
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.