Hi Aurelien,

Thanks for the help.

Actually I have to apply the patch on glibc2.3.6 version.
You have mentioned two patch links. Are both needed to be applied for this 
vulnerability?


-Thanks and Regards,
 Deepak Kumar

-----Original Message-----
From: Aurelien Jarno [mailto:aurel...@aurel32.net]
Sent: Wednesday, November 12, 2014 10:38 PM
To: Deepak Kumar
Cc: car...@systemhalted.org; mgilb...@debian.org; sub...@bugs.debian.org
Subject: Re: Bug#742925: Re: Bug#742925: eglibc: CVE-2013-4357

On Wed, Nov 12, 2014 at 09:35:37AM +0000, Deepak Kumar wrote:
> Hi All,
>
> Could anyone please help, with the vulnerability ID, CVE-2013-4357.
>
> Could you please help with the description of the vulnerability as in what is 
> the applicability of the vulnerability, and The patch for the vulnerability.

The description is available there:

https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4357
https://sourceware.org/bugzilla/show_bug.cgi?id=12671

> Which of the below mentioned patch is applicable for vulnerability.

The patches to fix the issue are available there:

https://sourceware.org/git/?p=glibc.git;a=commitdiff;h=f2962a71959fd254a7a223437ca4b63b9e81130c
https://sourceware.org/git/?p=glibc.git;a=commitdiff;h=34a9094f49241ebb72084c536cf468fd51ebe3ec

Aurelien

--
Aurelien Jarno                          GPG: 4096R/1DDD8C9B
aurel...@aurel32.net                 http://www.aurel32.net
"DISCLAIMER: This message is proprietary to Aricent and is intended solely for 
the use of the individual to whom it is addressed. It may contain privileged or 
confidential information and should not be circulated or used for any purpose 
other than for what it is intended. If you have received this message in error, 
please notify the originator immediately. If you are not the intended 
recipient, you are notified that you are strictly prohibited from using, 
copying, altering, or disclosing the contents of this message. Aricent accepts 
no responsibility for loss or damage arising from the use of the information 
transmitted by this email including damage from virus."


--
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to