Re: [CentOS] CVE-2014-4043 posix_spawn_file_actions_addopen

2015-05-26 Thread Johnny Hughes
On 05/26/2015 10:59 AM, Patrick Rael wrote: > Hi, > Is there an ETA on when CVE-2014-4043 for glibc will be fixed in > centos. > I see the upstream vendor version glibc-2.20 has this fix supposedly, but > I don't see this specific fix in the centos glibc changelogs. I've > compiled the > te

[CentOS] CVE-2014-4043 posix_spawn_file_actions_addopen

2015-05-26 Thread Patrick Rael
Hi, Is there an ETA on when CVE-2014-4043 for glibc will be fixed in centos. I see the upstream vendor version glibc-2.20 has this fix supposedly, but I don't see this specific fix in the centos glibc changelogs. I've compiled the test code for this bug and as of glibc-2.17.77 the test