Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-12133

Опубликовано: 07 сент. 2017
Источник: debian

Описание

Use-after-free vulnerability in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) before 2.26 allows remote attackers to have unspecified impact via vectors related to error path.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
glibcfixed2.24-15package
glibcfixed2.24-11+deb9u2stretchpackage
eglibcremovedpackage
eglibcno-dsawheezypackage

Примечания

  • issue introduced by fix for CVE-2016-4429

  • https://sourceware.org/bugzilla/show_bug.cgi?id=21115

  • https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=d42eed4a044e5e10dfb885cf9891c2518a72a491

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 8 лет назад

Use-after-free vulnerability in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) before 2.26 allows remote attackers to have unspecified impact via vectors related to error path.

CVSS3: 3.7
redhat
почти 9 лет назад

Use-after-free vulnerability in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) before 2.26 allows remote attackers to have unspecified impact via vectors related to error path.

CVSS3: 5.9
nvd
больше 8 лет назад

Use-after-free vulnerability in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) before 2.26 allows remote attackers to have unspecified impact via vectors related to error path.

suse-cvrf
почти 8 лет назад

Security update for glibc

suse-cvrf
почти 8 лет назад

Security update for glibc