[CentOS] install older version of glibc package

Mon Oct 25 09:56:34 UTC 2010
Peter Kjellstrom <cap at nsc.liu.se>

On Monday 25 October 2010, Sherin George wrote:
> Thanks you so much Peter.
>
> I thought it is fixed in latest centos rpm.

CVE-2010-3847 is fixed in 2.5-49.el5_5.6
CVE-2010-3856 has no released fix (afaik):
 http://seclists.org/fulldisclosure/2010/Oct/344

> I got "custom packaged of glibc" from a third party(which I know as
> reliable) site.
>
> Do you have any information about availability of a patched replacement at
> this time?

Nope

/Peter
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part.
URL: <http://lists.centos.org/pipermail/centos/attachments/20101025/0fff1a4c/attachment-0005.sig>