PT-2012-1064 · Gnu+3 · Glibc+3

Dividead

+2

·

Published

2012-01-05

·

Updated

2024-06-15

·

CVE-2009-5029

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions glibc versions 2.3.4 glibc versions prior to 2.15-r3
Description The issue concerns multiple vulnerabilities in the glibc package, which can lead to a disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited locally. The vulnerabilities may cause a denial of service (crash) and possibly execute arbitrary code via a crafted timezone (TZ) file.
Recommendations For glibc versions 2.3.4, consider updating to a version prior to 2.15-r3 to resolve the issue. For glibc versions prior to 2.15-r3, update to version 2.15-r3 or later to resolve the issue. As a temporary workaround, consider restricting access to the tzfile read function until a patch is available.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-05982
BDU:2015-05983
BDU:2015-05984
BDU:2015-05985
BDU:2015-05986
BDU:2015-05987
BDU:2015-06020
BDU:2015-08584
BDU:2015-08585
BDU:2015-08586
BDU:2015-08587
BDU:2015-08588
BDU:2015-08589
BDU:2015-09685
CESA-2012_0058
CVE-2009-5029
OPENSUSE-SU-2012_0064-1
OPENSUSE-SU-2024:10154-1
RHSA-2012:0058
RHSA-2012:0125
RHSA-2012:0126
RHSA-2012_0058
RHSA-2012_0125
RHSA-2012_0126
SUSE-SU-2013_1287-1

Affected Products

Centos
Red Hat
Suse
Glibc