PT-2001-1047 · Red Hat+1 · Red Hat+1

Published

2001-12-21

·

Updated

2018-05-03

·

CVE-2001-0886

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions glibc versions 2.1.3 through 2.2.4 glibc-common versions 2.1.3 through 2.2.4 glibc-devel versions 2.1.3 through 2.2.4 glibc-profile versions 2.1.3 through 2.2.4
Description The issue affects the glibc package in Red Hat Linux, allowing for remote exploitation that may lead to a breach of confidentiality, integrity, and availability of protected information. A buffer overflow in the glob function of glibc can cause a denial of service and possibly execute arbitrary code via a glob pattern that ends in a brace "{" character.
Recommendations For glibc versions 2.1.3 through 2.2.4, consider updating to a newer version to mitigate the risk. For glibc-common versions 2.1.3 through 2.2.4, consider updating to a newer version to mitigate the risk. For glibc-devel versions 2.1.3 through 2.2.4, consider updating to a newer version to mitigate the risk. For glibc-profile versions 2.1.3 through 2.2.4, consider updating to a newer version to mitigate the risk. As a temporary workaround, consider restricting access to the glob function to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-07993
BDU:2015-07994
BDU:2015-07997
BDU:2015-08004
BDU:2015-08005
BDU:2015-08008
BDU:2015-08009
CVE-2001-0886

Affected Products

Red Hat
Glibc