USN-6620-1: GNU C Library vulnerabilities
Published Feb 1, 2024
·Updated
It was discovered that the GNU C Library incorrectly handled the syslog() function call. A local attacker could use this issue to execute arbitrary code and possibly escalate privileges.
Affected Software
2 affected componentsFixes available
All of the following
ubuntu/libc6<2.38-1ubuntu6.1
2.38-1ubuntu6.1
Ubuntu Ubuntu=23.10
Event History
Feb 1, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-6620-1?
The severity of USN-6620-1 is high due to the potential for local code execution and privilege escalation.
2
How do I fix USN-6620-1?
To fix USN-6620-1, update the GNU C Library package to version 2.38-1ubuntu6.1 on Ubuntu 23.10.
3
Which systems are affected by USN-6620-1?
USN-6620-1 affects Ubuntu 23.10 systems that use libc6 version prior to 2.38-1ubuntu6.1.
4
Can USN-6620-1 be exploited remotely?
No, USN-6620-1 requires local access to the system to exploit the vulnerability.
5
What does USN-6620-1 involve in terms of security risks?
USN-6620-1 involves risks of arbitrary code execution which can lead to privilege escalation on the affected system.