PT-2008-6882 · Gnu+1 · Libc6+2

Maksymilian Arciemowicz

·

Published

1970-01-01

·

Updated

2017-08-17

·

CVE-2009-4881

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions glibc versions prior to 2.10.1 libc6 versions prior to 2.11.2-r3
Description The issue is related to multiple vulnerabilities in the glibc and libc6 packages of the Debian GNU/Linux operating system. These vulnerabilities can lead to a disruption of confidentiality, integrity, and availability of protected information. The exploitation of these vulnerabilities can be carried out remotely. A specific example of such a vulnerability is an integer overflow in the vstrfmon l function, which allows context-dependent attackers to cause a denial of service via a crafted format string.
Recommendations For glibc versions prior to 2.10.1, update to version 2.10.1 or later to resolve the issue. For libc6 versions prior to 2.11.2-r3, update to version 2.11.2-r3 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable functions until a patch is available.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-01134
BDU:2015-01135
BDU:2015-01136
BDU:2015-01137
BDU:2015-01138
BDU:2015-01139
BDU:2015-01140
BDU:2015-01141
BDU:2015-01142
BDU:2015-01143
BDU:2015-01144
BDU:2015-01145
BDU:2015-01146
BDU:2015-01147
BDU:2015-01148
BDU:2015-01149
BDU:2015-01150
BDU:2015-01151
BDU:2015-01152
BDU:2015-01153
BDU:2015-01154
BDU:2015-01155
BDU:2015-01156
BDU:2015-01157
BDU:2015-01158
BDU:2015-01159
BDU:2015-01160
BDU:2015-01161
BDU:2015-01162
BDU:2015-01163
BDU:2015-01164
BDU:2015-01165
BDU:2015-01166
BDU:2015-01167
BDU:2015-01168
BDU:2015-01169
BDU:2015-01170
BDU:2015-09412
CVE-2009-4881
DSA-2058-1

Affected Products

Debian
Glibc
Libc6