Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-1000408

Опубликовано: 01 фев. 2018
Источник: debian
EPSS Низкий

Описание

A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
glibcfixed2.25-5package
glibcfixed2.24-11+deb9u4stretchpackage
eglibcremovedpackage
eglibcno-dsawheezypackage

Примечания

  • https://www.openwall.com/lists/oss-security/2017/12/11/4

EPSS

Процентиль: 73%
0.00761
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 8 лет назад

A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366.

CVSS3: 3.3
redhat
около 8 лет назад

A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366.

CVSS3: 7.8
nvd
около 8 лет назад

A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366.

CVSS3: 7.8
github
больше 3 лет назад

A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366.

CVSS3: 7.8
fstec
около 8 лет назад

Уязвимость динамического загрузчика ld.so библиотеки, обеспечивающей системные вызовы и основные фунции glibc, позволяющая нарушителю вызвать утечку памяти

EPSS

Процентиль: 73%
0.00761
Низкий