PT-2024-1610 · Glibc+2 · Glibc+2
Guilherme De Almeida Suckevicz
·
Published
2024-01-30
·
Updated
2024-03-26
·
CVE-2023-6780
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
glibc versions 2.37 and newer
Description
The issue is related to an integer overflow in the
vsyslog internal function of the glibc library, which is called by the syslog and vsyslog functions. This occurs when these functions are called with a very long message, leading to an incorrect calculation of the buffer size to store the message, resulting in undefined behavior.Recommendations
For glibc versions 2.37 and newer, consider disabling the
vsyslog internal function or restricting the use of the syslog and vsyslog functions until a patch is available. Additionally, avoid using very long messages with these functions to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Ubuntu
Glibc