PT-2017-4267 · Gnu+5 · Glibc+5

Publicado

2017-06-19

·

Atualizado

2024-06-15

·

CVE-2017-1000366

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions glibc versions 2.25 and earlier
Description The issue is related to a buffer overflow in memory, allowing an attacker to access confidential data, compromise its integrity, and cause a denial of service. Additionally, it is possible to manipulate the heap/stack using specially crafted LD LIBRARY PATH values, potentially resulting in arbitrary code execution.
Recommendations For glibc versions 2.25 and earlier, consider applying additional hardening changes to prevent manipulation of stack and heap memory as a temporary mitigation measure. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-2833
BDU:2023-07722
CESA-2017_1480
CESA-2017_1481
CVE-2017-1000366
DLA-992-1
DSA-3887-1
MGASA-2017-0184
OPENSUSE-SU-2017_1629-1
OPENSUSE-SU-2024:10792-1
RHSA-2017:1479
RHSA-2017:1480
RHSA-2017:1481
RHSA-2017_1479
RHSA-2017_1480
RHSA-2017_1481
SUSE-SU-2017:1611-1
SUSE-SU-2017:1614-1
SUSE-SU-2017:1619-1
SUSE-SU-2017:1621-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
SUSE-SU-2017_1611-1
SUSE-SU-2017_1614-1
SUSE-SU-2017_1619-1
SUSE-SU-2017_1621-1
USN-3323-1
USN-3323-2

Produtos afetados

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Glibc