PT-2011-1090 · Gnu+1 · Libc6+8

Publicado

2011-04-04

·

Atualizado

2018-10-09

·

CVE-2011-1659

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions glibc versions 2.3.4 through 2.13 glibc-utils versions 2.3.4 glibc-common versions 2.3.4 glibc-devel versions 2.3.4 glibc-profile versions 2.3.4 glibc-headers versions 2.3.4 nptl-devel version 2.3.4
Description The issue involves multiple vulnerabilities in the glibc package, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited locally. Specifically, an integer overflow in posix/fnmatch.c in the GNU C Library (aka glibc or libc6) 2.13 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long UTF8 string that is used in an fnmatch call with a crafted pattern argument.
Recommendations For glibc versions 2.3.4 through 2.13, update to a version later than 2.13 to resolve the issue. For glibc-utils versions 2.3.4, update to a version later than 2.3.4 to resolve the issue. For glibc-common versions 2.3.4, update to a version later than 2.3.4 to resolve the issue. For glibc-devel versions 2.3.4, update to a version later than 2.3.4 to resolve the issue. For glibc-profile versions 2.3.4, update to a version later than 2.3.4 to resolve the issue. For glibc-headers versions 2.3.4, update to a version later than 2.3.4 to resolve the issue. For nptl-devel version 2.3.4, update to a version later than 2.3.4 to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable glibc functions until a patch is available.

Exploit

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-05982
BDU:2015-05983
BDU:2015-05984
BDU:2015-05985
BDU:2015-05986
BDU:2015-05987
BDU:2015-06020
BDU:2015-08584
BDU:2015-08585
BDU:2015-08586
BDU:2015-08587
BDU:2015-08588
BDU:2015-08589
BDU:2015-09685
CVE-2011-1659
RHSA-2011:0412
RHSA-2011:0413
RHSA-2011_0412
RHSA-2011_0413
RHSA-2012:0125
RHSA-2012_0125

Produtos afetados

Red Hat
Glibc
Glibc-Common
Glibc-Devel
Glibc-Headers
Glibc-Profile
Glibc-Utils
Libc6
Nptl-Devel