OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: UNIX locale format string vulnerability
From: Bob Manson (bobECF.UTORONTO.CA)
Date: Mon Sep 04 2000 - 16:34:03 CDT


I immediately grabbed the new rpms from update.redhat.com, followed the
instructions and got:

glibc
##################################################
package zic not found in file index
package ca_ES not found in file index
package sl_SI not listed in file index
package ca_ES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package sl_SI not listed in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package LC_MESSAGES not found in file index
package Indianapolis not listed in file index
package Indianapolis not listed in file index
package Nicosia not listed in file index
package Indianapolis not listed in file index
package Indianapolis not listed in file index
package Nicosia not listed in file index
package Indianapolis not listed in file index
package Indianapolis not listed in file index
package Nicosia not listed in file index
execution of glibc-devel-2.1.3-19 script failed, exit status 0

I am now well and truly screwed. I can run ls, but ls -l fails with a
"Segmentation fault" as do many other commands, so I can't even look to
see if I've got any zero length lib files.

I am (I was) running:

Red Hat Linux release 6.2 (Zoot)
Kernel 2.2.16-3 on an i686

Any suggestions?

        thanks,
        bob

---------------------------------------------------------------------
Bob Manson Phone (416)978-5898
Systems Administrator, ECF Fax (416)978-7320
University of Toronto email bobecf.utoronto.ca
Toronto, Canada M5S 1A4 or bobecf.toronto.edu

"It is preferable not to travel with a dead man." --- Henri Michaux