Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-7309

Опубликовано: 03 фев. 2019
Источник: debian
EPSS Низкий

Описание

In the GNU C Library (aka glibc or libc6) through 2.29, the memcmp function for the x32 architecture can incorrectly return zero (indicating that the inputs are equal) because the RDX most significant bit is mishandled.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
glibcfixed2.28-6package

Примечания

  • https://sourceware.org/bugzilla/show_bug.cgi?id=24155

  • https://sourceware.org/ml/libc-alpha/2019-02/msg00041.html

  • x32 not officially supported

EPSS

Процентиль: 46%
0.00607
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 7 лет назад

In the GNU C Library (aka glibc or libc6) through 2.29, the memcmp function for the x32 architecture can incorrectly return zero (indicating that the inputs are equal) because the RDX most significant bit is mishandled.

CVSS3: 3.3
redhat
больше 7 лет назад

In the GNU C Library (aka glibc or libc6) through 2.29, the memcmp function for the x32 architecture can incorrectly return zero (indicating that the inputs are equal) because the RDX most significant bit is mishandled.

CVSS3: 5.5
nvd
больше 7 лет назад

In the GNU C Library (aka glibc or libc6) through 2.29, the memcmp function for the x32 architecture can incorrectly return zero (indicating that the inputs are equal) because the RDX most significant bit is mishandled.

CVSS3: 5.5
msrc
почти 6 лет назад

Описание отсутствует

CVSS3: 5.5
github
около 4 лет назад

In the GNU C Library (aka glibc or libc6) through 2.29, the memcmp function for the x32 architecture can incorrectly return zero (indicating that the inputs are equal) because the RDX most significant bit is mishandled.

EPSS

Процентиль: 46%
0.00607
Низкий