PT-2014-1818 · Gnu+4 · Glibc+4

Publicado

2014-11-24

·

Atualizado

2024-06-15

·

CVE-2014-7817

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions glibc versions 2.12 glibc-common versions 2.12 glibc-devel versions 2.12 glibc-debuginfo versions 2.12 glibc-debuginfo-common versions 2.12 glibc-headers versions 2.12 glibc-static versions 2.12 glibc-utils versions 2.12
Description The issue concerns multiple vulnerabilities in the glibc package, which can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The wordexp function in GNU C Library (aka glibc) does not enforce the WRDE NOCMD flag, allowing context-dependent attackers to execute arbitrary commands, as demonstrated by input containing "$((...))".
Recommendations For glibc versions 2.12, update to a newer version to mitigate the risk. For glibc-common versions 2.12, update to a newer version to mitigate the risk. For glibc-devel versions 2.12, update to a newer version to mitigate the risk. For glibc-debuginfo versions 2.12, update to a newer version to mitigate the risk. For glibc-debuginfo-common versions 2.12, update to a newer version to mitigate the risk. For glibc-headers versions 2.12, update to a newer version to mitigate the risk. For glibc-static versions 2.12, update to a newer version to mitigate the risk. For glibc-utils versions 2.12, update to a newer version to mitigate the risk. As a temporary workaround, consider restricting access to the wordexp function until a patch is available.

Exploit

Correção

Buffer Overflow

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-06193
BDU:2015-06194
BDU:2015-06195
BDU:2015-06196
BDU:2015-06197
BDU:2015-06198
BDU:2015-06199
BDU:2015-06200
BDU:2015-09219
BDU:2015-09220
BDU:2015-09221
BDU:2015-09222
BDU:2015-09223
BDU:2015-09224
BDU:2015-09225
BDU:2015-09226
CESA-2014_2023
CESA-2015_0016
CVE-2014-7817
DLA-97-1
DSA-3142-1
MGASA-2014-0496
OPENSUSE-SU-2024:10154-1
RHSA-2014:2023
RHSA-2014_2023
RHSA-2015:0016
RHSA-2015_0016
SUSE-RU-2015:0794-1
SUSE-SU-2015:0253-1
SUSE-SU-2015:0439-1
SUSE-SU-2015:0526-1
SUSE-SU-2015:0551-1
USN-2432-1

Produtos afetados

Centos
Red Hat
Suse
Ubuntu
Glibc