PT-2012-1186 · Gnu+3 · Gnu C Library+3
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
GNU C Library (aka glibc or libc6) version 2.16
Description
The issue is caused by multiple integer overflows in various functions, including
strtod, strtof, strtold, and strtod l, within the stdlib component of the GNU C Library. This can lead to a denial of service, resulting in an application crash, and potentially allow the execution of arbitrary code. The exploitation occurs when a long string is used, triggering a stack-based buffer overflow.Recommendations
For GNU C Library (aka glibc or libc6) version 2.16, consider updating to a newer version that addresses the integer overflows in the affected functions. As a temporary workaround, restrict the use of the
strtod, strtof, strtold, and strtod l functions to minimize the risk of exploitation. Avoid using long strings that could trigger the stack-based buffer overflow in these functions.Exploit
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Centos
Gnu C Library
Red Hat
Suse