PT-2017-4267 · Gnu+5 · Glibc+5
Publicado
2017-06-19
·
Atualizado
2024-06-15
·
CVE-2017-1000366
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
glibc versions 2.25 and earlier
Description
The issue is related to a buffer overflow in memory, allowing an attacker to access confidential data, compromise its integrity, and cause a denial of service. Additionally, it is possible to manipulate the heap/stack using specially crafted LD LIBRARY PATH values, potentially resulting in arbitrary code execution.
Recommendations
For glibc versions 2.25 and earlier, consider applying additional hardening changes to prevent manipulation of stack and heap memory as a temporary mitigation measure.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Red Hat
Suse
Ubuntu
Glibc