PT-2001-1047 · Red Hat+1 · Red Hat+1
Published
2001-12-21
·
Updated
2018-05-03
·
CVE-2001-0886
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
glibc versions 2.1.3 through 2.2.4
glibc-common versions 2.1.3 through 2.2.4
glibc-devel versions 2.1.3 through 2.2.4
glibc-profile versions 2.1.3 through 2.2.4
Description
The issue affects the glibc package in Red Hat Linux, allowing for remote exploitation that may lead to a breach of confidentiality, integrity, and availability of protected information. A buffer overflow in the glob function of glibc can cause a denial of service and possibly execute arbitrary code via a glob pattern that ends in a brace "{" character.
Recommendations
For glibc versions 2.1.3 through 2.2.4, consider updating to a newer version to mitigate the risk.
For glibc-common versions 2.1.3 through 2.2.4, consider updating to a newer version to mitigate the risk.
For glibc-devel versions 2.1.3 through 2.2.4, consider updating to a newer version to mitigate the risk.
For glibc-profile versions 2.1.3 through 2.2.4, consider updating to a newer version to mitigate the risk.
As a temporary workaround, consider restricting access to the glob function to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat
Glibc