PT-2008-6878 · Gnu+1 · Libc6+2

Dan Rosenberg

·

Published

1970-01-01

·

Updated

2017-08-17

·

CVE-2010-0830

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions glibc versions 2.0.1 through 2.11.1 glibc-2.3.4 libc6 versions prior to 2.11.2-r3 libc6-dev-i386 libc6-dev-sparc64 libc6-dev-mips64 libc6-dev-ppc64 libc6-dev-s390x libc6-dev-mipsn32 libc6-dev-amd64 libc6 libc6-sparcv9b libc6-mipsn32 libc6-udeb libc6.1-dbg libc6.1-dev libc6.1-pic libc6.1-udeb libc6.1 libc6-amd64 libc6-i386 libc6-i686 libc6-mips64 libc6-ppc64 libc6-s390x libc6-dbg libc6-pic libc6.1-alphaev67 glibc-profile-2.3.4 glibc-profile-64bit glibc-headers-2.3.4 glibc-common-2.3.4 glibc-utils-2.3.4 glibc-devel-2.3.4 glibc-devel-64bit glibc-dceext glibc-dceext-32bit glibc-locale-64bit glibc-debuginfo nptl-devel-2.3.4 nscd libnss-dns-udeb libnss-files-udeb locales locales-all
Description The issue is related to multiple vulnerabilities in the glibc library, which provides system calls and basic functions. These vulnerabilities can lead to a breach of confidentiality, integrity, and availability of protected information. The exploitation of these vulnerabilities can be performed remotely or locally, depending on the specific vulnerability and the system configuration. One of the vulnerabilities is an integer signedness error in the elf get dynamic info function, which can allow a remote attacker to execute arbitrary code with the help of a specially crafted ELF program containing a negative value for a certain d tag structure member in the ELF header.
Recommendations As a temporary workaround, consider disabling the elf get dynamic info function until a patch is available. Restrict access to the vulnerable glibc library to minimize the risk of exploitation. Avoid using the glibc library until the issue is resolved. Update glibc to version 2.11.2-r3 or later. Update libc6 to version 2.11.2-r3 or later. For each affected version, apply the corresponding patch or update to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-01134
BDU:2015-01135
BDU:2015-01136
BDU:2015-01137
BDU:2015-01138
BDU:2015-01139
BDU:2015-01140
BDU:2015-01141
BDU:2015-01142
BDU:2015-01143
BDU:2015-01144
BDU:2015-01145
BDU:2015-01146
BDU:2015-01147
BDU:2015-01148
BDU:2015-01149
BDU:2015-01150
BDU:2015-01151
BDU:2015-01152
BDU:2015-01153
BDU:2015-01154
BDU:2015-01155
BDU:2015-01156
BDU:2015-01157
BDU:2015-01158
BDU:2015-01159
BDU:2015-01160
BDU:2015-01161
BDU:2015-01162
BDU:2015-01163
BDU:2015-01164
BDU:2015-01165
BDU:2015-01166
BDU:2015-01167
BDU:2015-01168
BDU:2015-01169
BDU:2015-01170
BDU:2015-04440
BDU:2015-04441
BDU:2015-04442
BDU:2015-04443
BDU:2015-04444
BDU:2015-04445
BDU:2015-04446
BDU:2015-04447
BDU:2015-05982
BDU:2015-05983
BDU:2015-05984
BDU:2015-05985
BDU:2015-05986
BDU:2015-05987
BDU:2015-06020
BDU:2015-08584
BDU:2015-08585
BDU:2015-08586
BDU:2015-08587
BDU:2015-08588
BDU:2015-08589
BDU:2015-09412
BDU:2017-00284
CVE-2010-0830
DSA-2058-1
RHSA-2012:0125
RHSA-2012:0126
RHSA-2012_0125
RHSA-2012_0126

Affected Products

Red Hat
Glibc
Libc6