PT-2014-2127 · Gnu · Eglibc+1
Published
2014-10-27
·
Updated
2023-02-13
·
CVE-2011-2702
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Glibc versions prior to 2.13
eglibc versions prior to 2.13
Description
The issue is related to an integer signedness error when using Supplemental Streaming SIMD Extensions 3 (SSSE3) optimization. This error allows context-dependent attackers to execute arbitrary code via a negative length parameter to certain functions, which triggers an out-of-bounds read. The affected functions include
memcpy-ssse3-rep.S, memcpy-ssse3.S, and memset-sse2.S in sysdeps/i386/i686/multiarch/.Recommendations
For Glibc versions prior to 2.13, update to version 2.13 or later.
For eglibc versions prior to 2.13, update to version 2.13 or later.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Glibc
Eglibc