PT-2012-1097 · Bdwgc+2 · Libgc+3

Ivan Maidanski

·

Published

2012-07-25

·

Updated

2016-09-29

·

CVE-2012-2673

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions gc versions 7.1 libgc versions prior to 7.2
Description The issue is related to multiple integer overflows in the GC generic malloc and calloc functions in malloc.c, and the GC generic malloc ignore off page function in mallocx.c. This can make it easier for attackers to perform memory-related attacks, such as buffer overflows, via a large size value, which causes less memory to be allocated than expected. The exploitation of this issue can be done remotely and may lead to a violation of the integrity of protected information.
Recommendations For gc versions 7.1, consider updating to version 7.2 or later to resolve the issue. For libgc versions prior to 7.2, update to version 7.2 or later to fix the integer overflows in the GC generic malloc, calloc, and GC generic malloc ignore off page functions. As a temporary workaround, consider restricting the use of the vulnerable functions until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-07721
BDU:2015-07722
BDU:2015-07723
BDU:2015-08841
BDU:2015-08842
BDU:2015-08843
CESA-2013_1500
CVE-2012-2673
OPENSUSE-SU-2024:10302-1
RHSA-2013:1500
RHSA-2013_1500
RHSA-2014:0149
RHSA-2014:0150

Affected Products

Centos
Red Hat
Gc
Libgc