PT-2010-5674 · Gnu+1 · Glibc+1
Tavis Ormandy
·
Published
1970-01-01
·
Updated
2023-02-13
·
CVE-2010-3847
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
glibc versions prior to 2.11.2-r3
glibc versions prior to 2.15-r3
glibc-dceext-32bit (affected versions not specified)
glibc-64bit (affected versions not specified)
glibc-profile-64bit (affected versions not specified)
glibc-obsolete (affected versions not specified)
glibc-locale-64bit (affected versions not specified)
glibc-dceext (affected versions not specified)
glibc-debuginfo (affected versions not specified)
glibc-devel-64bit (affected versions not specified)
Description
The issue involves multiple vulnerabilities in the glibc package, which can lead to breaches of confidentiality, integrity, and availability of protected information. Exploitation of these vulnerabilities can be carried out locally or remotely, depending on the specific vulnerability and system configuration. The vulnerabilities can be exploited by crafted dynamic shared objects or through other means, allowing attackers to gain privileges or disrupt system operations.
Recommendations
For glibc versions prior to 2.11.2-r3, update to version 2.11.2-r3 or later.
For glibc versions prior to 2.15-r3, update to version 2.15-r3 or later.
For glibc-dceext-32bit, glibc-64bit, glibc-profile-64bit, glibc-obsolete, glibc-locale-64bit, glibc-dceext, glibc-debuginfo, and glibc-devel-64bit, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat
Glibc