Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-0395

Опубликовано: 22 янв. 2025
Источник: debian
EPSS Низкий

Описание

When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
glibcfixed2.40-6package
glibcfixed2.36-9+deb12u10bookwormpackage

Примечания

  • https://sourceware.org/bugzilla/show_bug.cgi?id=32582

  • https://www.openwall.com/lists/oss-security/2025/01/22/4

  • Fixed by: https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=7d4b6bcae91f29d7b4daf15bab06b66cf1d2217c (2.40-branch)

  • Fixed by: https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=7971add7ee4171fdd8dfd17e7c04c4ed77a18845 (2.36-branch)

  • https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2025-0001

  • https://sourceware.org/pipermail/libc-announce/2025/000044.html

EPSS

Процентиль: 50%
0.00271
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
7 месяцев назад

When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.

CVSS3: 5.5
redhat
7 месяцев назад

When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.

CVSS3: 7.5
nvd
7 месяцев назад

When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.

CVSS3: 7.5
msrc
29 дней назад

Описание отсутствует

suse-cvrf
6 месяцев назад

Security update for glibc

EPSS

Процентиль: 50%
0.00271
Низкий