PT-2003-1082 · Gnu+1 · Glibc+7

Published

2003-09-03

·

Updated

2008-09-10

·

CVE-2003-0689

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions glibc versions 2.2.4 through 2.2.5 glibc versions 2.3.2 glibc-common versions 2.2.4 through 2.2.5 glibc-common version 2.3.2 glibc-debug versions 2.2.5 through 2.3.2 glibc-debug-static versions 2.2.5 through 2.3.2 glibc-devel versions 2.2.4 through 2.3.2 glibc-profile versions 2.2.4 through 2.3.2 glibc-utils versions 2.2.5 through 2.3.2
Description The issue affects the glibc package in Red Hat Linux, allowing attackers to cause a denial of service and execute arbitrary code when a user is a member of a large number of groups, which can cause a buffer overflow. The getgrouplist function in GNU libc is vulnerable. Exploitation of the vulnerabilities can lead to disruption of confidentiality, integrity, and availability of protected information and can be carried out remotely.
Recommendations For glibc versions 2.2.4 through 2.2.5, update to a version that fixes the getgrouplist function issue. For glibc versions 2.3.2, update to a version that fixes the getgrouplist function issue. For glibc-common versions 2.2.4 through 2.2.5, update to a version that fixes the getgrouplist function issue. For glibc-common version 2.3.2, update to a version that fixes the getgrouplist function issue. For glibc-debug versions 2.2.5 through 2.3.2, update to a version that fixes the getgrouplist function issue. For glibc-debug-static versions 2.2.5 through 2.3.2, update to a version that fixes the getgrouplist function issue. For glibc-devel versions 2.2.4 through 2.3.2, update to a version that fixes the getgrouplist function issue. For glibc-profile versions 2.2.4 through 2.3.2, update to a version that fixes the getgrouplist function issue. For glibc-utils versions 2.2.5 through 2.3.2, update to a version that fixes the getgrouplist function issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-07994
BDU:2015-07995
BDU:2015-07996
BDU:2015-07997
BDU:2015-07998
BDU:2015-07999
BDU:2015-08000
BDU:2015-08001
BDU:2015-08002
BDU:2015-08003
BDU:2015-08005
BDU:2015-08006
BDU:2015-08007
BDU:2015-08009
BDU:2015-08010
BDU:2015-08011
BDU:2015-08012
BDU:2015-08013
CVE-2003-0689

Affected Products

Red Hat
Glibc
Glibc-Common
Glibc-Debug
Glibc-Debug-Static
Glibc-Devel
Glibc-Profile
Glibc-Utils