Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-7309

Опубликовано: 03 фев. 2019
Источник: debian

Описание

In the GNU C Library (aka glibc or libc6) through 2.29, the memcmp function for the x32 architecture can incorrectly return zero (indicating that the inputs are equal) because the RDX most significant bit is mishandled.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
glibcfixed2.28-6package

Примечания

  • https://sourceware.org/bugzilla/show_bug.cgi?id=24155

  • https://sourceware.org/ml/libc-alpha/2019-02/msg00041.html

  • x32 not officially supported

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 7 лет назад

In the GNU C Library (aka glibc or libc6) through 2.29, the memcmp function for the x32 architecture can incorrectly return zero (indicating that the inputs are equal) because the RDX most significant bit is mishandled.

CVSS3: 3.3
redhat
около 7 лет назад

In the GNU C Library (aka glibc or libc6) through 2.29, the memcmp function for the x32 architecture can incorrectly return zero (indicating that the inputs are equal) because the RDX most significant bit is mishandled.

CVSS3: 5.5
nvd
около 7 лет назад

In the GNU C Library (aka glibc or libc6) through 2.29, the memcmp function for the x32 architecture can incorrectly return zero (indicating that the inputs are equal) because the RDX most significant bit is mishandled.

CVSS3: 5.5
msrc
больше 5 лет назад

Описание отсутствует

CVSS3: 5.5
github
больше 3 лет назад

In the GNU C Library (aka glibc or libc6) through 2.29, the memcmp function for the x32 architecture can incorrectly return zero (indicating that the inputs are equal) because the RDX most significant bit is mishandled.