ALAS2-2018-992

Affecting glibc-langpack-en package, versions <2.26-27.amzn2.0.4

Report new vulnerabilities
medium severity
Do your applications use this vulnerable package? Test your applications

NVD Description

Note: Versions mentioned in the description apply to the upstream glibc-langpack-en package. See Remediation section below for Amzn:2 relevant versions.

Package updates are available for Amazon Linux 2 that fix the following vulnerabilities: CVE-2018-6551: 1542119: CVE-2018-6551 glibc: integer overflow in malloc functions The malloc implementation in the GNU C Library (aka glibc or libc6), from version 2.24 to 2.26 on powerpc, and only in version 2.26 on i386, did not properly handle malloc calls with arguments close to SIZE_MAX and could return a pointer to a heap region that is smaller than requested, eventually leading to heap corruption. CVE-2018-6485: 1542102: CVE-2018-6485 glibc: Integer overflow in posix_memalign in memalign functions An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to return a pointer to a heap area that is too small, potentially leading to heap corruption.

Remediation

Upgrade Amzn:2 glibc-langpack-en to version 2.26-27.amzn2.0.4 or higher.

References

CVE
ALAS2-2018-992
Snyk ID
SNYK-AMZN2-GLIBCLANGPACKEN-509662
Published
13 Nov, 2019