[CentOS] install older version of glibc package

Peter Kjellstrom cap at nsc.liu.se
Mon Oct 25 08:57:27 UTC 2010


On Monday 25 October 2010, Sherin George wrote:
> Hello Guys,
>
> Recently, I have installed some custom packaged of glibc in servers I
> manage due to vulnerabilities. At that time, official centos packages
> were not available. Now, I want to roll back to centos versions.

Do note that this new (and probably your custom built) glibc is vulnerable to 
a new trival local root (so you may want to build yet another custom version 
instead of switching back):

 https://bugzilla.redhat.com/show_bug.cgi?id=cve-2010-3856

/Peter
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part.
URL: <http://lists.centos.org/pipermail/centos/attachments/20101025/362df1d7/attachment.sig>


More information about the CentOS mailing list