Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gxfx-pp2w-7f8c

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destination buffer leading to a buffer underflow and potential code execution.

In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destination buffer leading to a buffer underflow and potential code execution.

EPSS

Процентиль: 97%
0.45102
Средний

7.8 High

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 8 лет назад

In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destination buffer leading to a buffer underflow and potential code execution.

CVSS3: 7
redhat
почти 8 лет назад

In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destination buffer leading to a buffer underflow and potential code execution.

CVSS3: 7.8
nvd
почти 8 лет назад

In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destination buffer leading to a buffer underflow and potential code execution.

CVSS3: 7.8
debian
почти 8 лет назад

In glibc 2.26 and earlier there is confusion in the usage of getcwd() ...

suse-cvrf
почти 8 лет назад

Security update for glibc

EPSS

Процентиль: 97%
0.45102
Средний

7.8 High

CVSS3

Дефекты

CWE-787