Executive Summary
Summary | |
---|---|
Title | coreutils security, bug fix, and enhancement update |
Informations | |||
---|---|---|---|
Name | RHSA-2013:1652 | First vendor Publication | 2013-11-21 |
Vendor | RedHat | Last vendor Modification | 2013-11-21 |
Severity (Vendor) | Low | Revision | 02 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:N/I:N/A:P) | |||
---|---|---|---|
Cvss Base Score | 4.3 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Problem Description: Updated coreutils packages that fix three security issues, several bugs, and add two enhancements are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having low security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 3. Description: The coreutils package contains the core GNU utilities. It is a combination of the old GNU fileutils, sh-utils, and textutils packages. It was discovered that the sort, uniq, and join utilities did not properly restrict the use of the alloca() function. An attacker could use this flaw to crash those utilities by providing long input strings. (CVE-2013-0221, CVE-2013-0222, CVE-2013-0223) These updated coreutils packages include numerous bug fixes and two enhancements. Space precludes documenting all of these changes in this advisory. Users are directed to the Red Hat Enterprise Linux 6.5 Technical Notes, linked to in the References, for information on the most significant of these changes. All coreutils users are advised to upgrade to these updated packages, which contain backported patches to correct these issues and add these enhancements. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/site/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 747592 - segfault message supressed with su -c 816708 - id and groups commands sometimes lie 827199 - [RHEL6] tail -f doesn't work on panasas file systems 836557 - du gives bogus warning if named service is running 842040 - df -P gives new lines when where '\n' is in any of the /proc/mounts fields. 903464 - CVE-2013-0221 coreutils: segfault in "sort -d" and "sort -M" with long line input 903465 - CVE-2013-0222 coreutils: segfault in uniq with long line input 903466 - CVE-2013-0223 coreutils: segfault in "join -i" with long line input 908980 - Provide the conv=sparse option in dd 965654 - dd option status=noxfer is ignored 980061 - mv: fails to overwrite directory on cross-filesystem copy with EISDIR |
Original Source
Url : https://rhn.redhat.com/errata/RHSA-2013-1652.html |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
67 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
33 % | CWE-20 | Improper Input Validation |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:25908 | |||
Oval ID: | oval:org.mitre.oval:def:25908 | ||
Title: | RHSA-2013:1652: coreutils security, bug fix, and enhancement update (Low) | ||
Description: | Updated coreutils packages that fix three security issues, several bugs, and add two enhancements are now available for Red Hat Enterprise Linux 6. | ||
Family: | unix | Class: | patch |
Reference(s): | RHSA-2013:1652-02 CESA-2013:1652 CVE-2013-0221 CVE-2013-0222 CVE-2013-0223 | Version: | 3 |
Platform(s): | Red Hat Enterprise Linux 6 CentOS Linux 6 | Product(s): | coreutils |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:27427 | |||
Oval ID: | oval:org.mitre.oval:def:27427 | ||
Title: | ELSA-2013-1652 -- coreutils security, bug fix, and enhancement update (low) | ||
Description: | [8.4-31.0.1] - clean up empty file if cp is failed [Orabug 15973168] | ||
Family: | unix | Class: | patch |
Reference(s): | ELSA-2013-1652 CVE-2013-0221 CVE-2013-0222 CVE-2013-0223 | Version: | 3 |
Platform(s): | Oracle Linux 6 | Product(s): | coreutils |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Os | 3 | |
Os | 1 |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2015-09-14 | Name : The remote device is missing a vendor-supplied security patch. File : f5_bigip_SOL16859.nasl - Type : ACT_GATHER_INFO |
2015-05-26 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2015-381.nasl - Type : ACT_GATHER_INFO |
2014-11-12 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2013-1652.nasl - Type : ACT_GATHER_INFO |
2014-11-08 | Name : The remote Red Hat host is missing a security update. File : redhat-RHSA-2013-1527.nasl - Type : ACT_GATHER_INFO |
2014-06-13 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2013-74.nasl - Type : ACT_GATHER_INFO |
2014-06-13 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2013-75.nasl - Type : ACT_GATHER_INFO |
2013-12-14 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2013-261.nasl - Type : ACT_GATHER_INFO |
2013-12-10 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20131121_coreutils_on_SL6_x.nasl - Type : ACT_GATHER_INFO |
2013-11-27 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2013-1652.nasl - Type : ACT_GATHER_INFO |
2013-11-21 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2013-1652.nasl - Type : ACT_GATHER_INFO |
2013-09-26 | Name : The remote SuSE 11 host is missing one or more security updates. File : suse_11_coreutils-130917.nasl - Type : ACT_GATHER_INFO |
2013-04-20 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2013-023.nasl - Type : ACT_GATHER_INFO |
2013-02-04 | Name : The remote Fedora host is missing a security update. File : fedora_2013-1455.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-11-13 13:27:21 |
|
2014-02-17 11:57:38 |
|
2013-11-25 21:23:06 |
|
2013-11-23 22:14:33 |
|
2013-11-21 09:18:22 |
|