PT-2015-7847 · Gnu+3 · Glibc+3
Florian Weimer
+1
·
Publicado
2015-12-09
·
Atualizado
2022-03-21
·
CVE-2015-8983
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GNU C Library (aka glibc or libc6) versions prior to 2.22
Description
The issue is related to an integer overflow in the
IO wstr overflow function, which can lead to a denial of service (application crash) or possibly allow execution of arbitrary code. This is triggered by computing a size in bytes, resulting in a heap-based buffer overflow.Recommendations
For versions prior to 2.22, update to version 2.22 or later to resolve the issue. As a temporary workaround, consider restricting the use of the
IO wstr overflow function to minimize the risk of exploitation.Exploit
Correção
DoS
Integer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Suse
Ubuntu
Glibc