Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-1999-0199

Опубликовано: 09 нояб. 1999
Источник: redhat
CVSS3: 0
EPSS Низкий

Описание

manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion of a tree's root, which might allow attackers to access a dangling pointer in an application whose developer was unaware of a documentation update from 1999.

Отчет

Red Hat Product Security does not feel that this issue has any security impact because the CVE description suggests that a missing statement in the manpage could lead to a generalized developer awareness problem, that in turn could potentially lead to a flaw. Thus, there is no actual exploitable vulnerability reported in this CVE, but rather, the possibility that one could occur in some unspecified software which uses glibc where the developers haven't read the manpage since 1999. There is no direct way for a vulnerability to come to fruition in software based solely on developer knowledge (or lack thereof), but an implementation of that knowledge, which is absent from the description of this issue. This manpage issue does not affect glibc as shipped with Red Hat Enterprise Linux 5, 6, 7, or 8 as the versions of glibc shipped already have the updated manpage.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5glibcNot affected
Red Hat Enterprise Linux 6glibcNot affected
Red Hat Enterprise Linux 7glibcNot affected
Red Hat Enterprise Linux 8glibcNot affected

Показывать по

Дополнительная информация

Дефект:
CWE-1053
https://bugzilla.redhat.com/show_bug.cgi?id=1885775glibc: manual/search.texi lacks a statement about the unspecified tdelete return value upon deletion of a tree's root

EPSS

Процентиль: 70%
0.00677
Низкий

0 Low

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 4 лет назад

manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion of a tree's root, which might allow attackers to access a dangling pointer in an application whose developer was unaware of a documentation update from 1999.

CVSS3: 9.8
debian
больше 4 лет назад

manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a ...

github
около 3 лет назад

manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion of a tree's root, which might allow attackers to access a dangling pointer in an application whose developer was unaware of a documentation update from 1999.

EPSS

Процентиль: 70%
0.00677
Низкий

0 Low

CVSS3