PT-2020-7012 · Gnu · Glibc
Published
2020-10-06
·
Updated
2020-12-03
·
CVE-1999-0199
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
glibc versions prior to 2.2
Description
The issue is related to the manual/search.texi in the GNU C Library, where a lack of documentation about the return value of the tdelete function when deleting a tree's root might allow attackers to access a dangling pointer. This could potentially be exploited in applications where the developer was not aware of a documentation update from 1999.
Recommendations
For versions prior to 2.2, update to version 2.2 or later to resolve the issue.
Exploit
Fix
Unchecked Return Value
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Glibc