PT-2012-1097 · Bdwgc+2 · Libgc+3

Ivan Maidanski

·

Publicado

2012-07-25

·

Atualizado

2016-09-29

·

CVE-2012-2673

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions gc versions 7.1 libgc versions prior to 7.2
Description The issue is related to multiple integer overflows in the GC generic malloc and calloc functions in malloc.c, and the GC generic malloc ignore off page function in mallocx.c. This can make it easier for attackers to perform memory-related attacks, such as buffer overflows, via a large size value, which causes less memory to be allocated than expected. The exploitation of this issue can be done remotely and may lead to a violation of the integrity of protected information.
Recommendations For gc versions 7.1, consider updating to version 7.2 or later to resolve the issue. For libgc versions prior to 7.2, update to version 7.2 or later to fix the integer overflows in the GC generic malloc, calloc, and GC generic malloc ignore off page functions. As a temporary workaround, consider restricting the use of the vulnerable functions until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-07721
BDU:2015-07722
BDU:2015-07723
BDU:2015-08841
BDU:2015-08842
BDU:2015-08843
CESA-2013_1500
CVE-2012-2673
OPENSUSE-SU-2024:10302-1
RHSA-2013:1500
RHSA-2013_1500
RHSA-2014:0149
RHSA-2014:0150

Produtos afetados

Centos
Red Hat
Gc
Libgc