Wind River Support Network

HomeDefectsLIN7-8298
Fixed

LIN7-8298 : Security Advisory - glibc - CVE-2017-1000366

Created: Jun 18, 2017    Updated: Mar 14, 2019
Resolved Date: Jul 3, 2017
Found In Version: 7.0.0.25
Fix Version: 7.0.0.26
Severity: Severe
Applicable for: Wind River Linux 7
Component/s: Toolchain

Description

This is an issue referred to as 'stack smash'.  See https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt for additional details.

Workaround

glibc:
(1) Apply the attached preliminary patch to layers/oe-core after the project has been configured, and 
(2) add
  USE_SDK_GLIBC = "0"
to local.conf

Other Downloads


CVEs


Live chat
Online