X-Git-Url: http://git.ipfire.org/?a=blobdiff_plain;f=NEWS;h=c1054ccbdb156b23d7526f2f3893096e92b370ba;hb=b13b96ca05a132a12dc5f3712b99e626670716bf;hp=fb4228330adff1b5da60f4295b8570de53f07daf;hpb=e1b6cb04f5efff7fb7415c69511d3ab3c31c6e4a;p=thirdparty%2Fglibc.git diff --git a/NEWS b/NEWS index fb4228330ad..c1054ccbdb1 100644 --- a/NEWS +++ b/NEWS @@ -44,10 +44,9 @@ Version 2.22 Hat). These updates cause user visible changes, such as the fix for bug 17998. -* CVE-2014-8121 The NSS files backend would reset the file pointer used by - the get*ent functions if any of the query functions for the same database - are used during the iteration, causing a denial-of-service condition in - some applications. +* CVE-2014-8121 The NSS backends shared internal state between the getXXent + and getXXbyYY NSS calls for the same database, causing a denial-of-service + condition in some applications. Version 2.21