Vulnerability Bulletins

IBM Security Bulletin: Vulnerabilities in Open Source glibc affect IBM Security Identity Governance (CVE-2014-8121)

   
Affected software IBM
 
Vulnerabilities in Open Source glibc that is used by IBM Security Identity Governance. GNU C Library (glibc) is vulnerable to a denial of service, caused by the failure to properly check if a file is open by DB_LOOKUP in nss_files/files-XXX.c in the Name Service Switch (NSS). By performing a look-up on a database while iterating over it, an attacker could exploit this vulnerability to cause the application to enter into an infinite loop CVE(s): CVE-2014-8121Affected product(s) and affected

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerabilities_in_open_source_glibc_affect_ibm_security_identity_governance_cve_2014_8121?lang=en_us