[CentOS] install older version of glibc package
Oct 26, 2010 at 12:12 am
RHEL has released patched RPMS.
Patiently waiting for centos RPMs :)
: CVE-2010-3847 is fixed in 2.5-49.el5_5.6 CVE-2010-3856 has no released fix (afaik): http://seclists.org/fulldisclosure/2010/Oct/344 Nope /Peter -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 189 bytes Desc: This is a digitally signed message part. Url : http://lists.centos.org/pipermail/centos/attachments/20101025/0fff1a4c/attachment.bin
: For completeness, Turns out that getting root with 3856 on CentOS-5 atleast isn't copy-n-paste-trivial. The suggested exploit using libpcprofile.so fails since that file comes from glibc-utils which (afaict) typically isn't installed. That said, it seems very likely that there are other ways to exploit 3856 on CentOS-5 so do not in any way interpret this as "lets skip the update". /Peter -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type:
[CentOS] Is there a problem with C6 CR and glibc?
[CentOS] Help with kickstart install
[CentOS] error installing Twinkle - libresolv.so.2(GLIBC_PRIVATE)
[CentOS] rpm -q versus what's installed
[CentOS] 5.2 to 5.4
[CentOS] Update for 5.3 failed on subversion and gstreamer-plugins-good
[CentOS] LD_ASSUME_KERNEL library issues CentOS 5 x86_64
[CentOS] Centos 4.5 clamav update error
[CentOS] why glibc-profile package get obsolete?
6 of 7
Oct 24, '10 at 11:27p
Oct 26, '10 at 5:34a
2 users in discussion
Sherin George (4)
Peter Kjellström (3)
Groups & Organizations
site design / logo © 2022 Grokbase