PT-2010-5674 · Gnu+1 · Glibc+1

Tavis Ormandy

·

Published

1970-01-01

·

Updated

2023-02-13

·

CVE-2010-3847

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions glibc versions prior to 2.11.2-r3 glibc versions prior to 2.15-r3 glibc-dceext-32bit (affected versions not specified) glibc-64bit (affected versions not specified) glibc-profile-64bit (affected versions not specified) glibc-obsolete (affected versions not specified) glibc-locale-64bit (affected versions not specified) glibc-dceext (affected versions not specified) glibc-debuginfo (affected versions not specified) glibc-devel-64bit (affected versions not specified)
Description The issue involves multiple vulnerabilities in the glibc package, which can lead to breaches of confidentiality, integrity, and availability of protected information. Exploitation of these vulnerabilities can be carried out locally or remotely, depending on the specific vulnerability and system configuration. The vulnerabilities can be exploited by crafted dynamic shared objects or through other means, allowing attackers to gain privileges or disrupt system operations.
Recommendations For glibc versions prior to 2.11.2-r3, update to version 2.11.2-r3 or later. For glibc versions prior to 2.15-r3, update to version 2.15-r3 or later. For glibc-dceext-32bit, glibc-64bit, glibc-profile-64bit, glibc-obsolete, glibc-locale-64bit, glibc-dceext, glibc-debuginfo, and glibc-devel-64bit, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Link Following

Weakness Enumeration

Related Identifiers

BDU:2015-04440
BDU:2015-04441
BDU:2015-04442
BDU:2015-04443
BDU:2015-04444
BDU:2015-04445
BDU:2015-04446
BDU:2015-04447
BDU:2015-09412
BDU:2015-09685
CVE-2010-3847
DSA-2122-1
DSA-2122-2
RHSA-2010:0787
RHSA-2010:0872
RHSA-2010_0787
RHSA-2010_0872

Affected Products

Red Hat
Glibc