Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-5029

Опубликовано: 01 июн. 2009
Источник: redhat
CVSS2: 6.5
EPSS Низкий

Описание

Integer overflow in the __tzfile_read function in glibc before 2.15 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted timezone (TZ) file, as demonstrated using vsftpd.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 3compat-glibcAffected
Red Hat Enterprise Linux 3glibcAffected
Red Hat Enterprise Linux 4compat-glibcAffected
Red Hat Enterprise Linux 5compat-glibcAffected
Red Hat Enterprise Linux 6compat-glibcAffected
Red Hat Enterprise Linux 4glibcFixedRHSA-2012:012513.02.2012
Red Hat Enterprise Linux 5glibcFixedRHSA-2012:012613.02.2012
Red Hat Enterprise Linux 6glibcFixedRHSA-2012:005824.01.2012

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=761245glibc: __tzfile_read integer overflow to buffer overflow

EPSS

Процентиль: 86%
0.02765
Низкий

6.5 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 12 лет назад

Integer overflow in the __tzfile_read function in glibc before 2.15 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted timezone (TZ) file, as demonstrated using vsftpd.

nvd
больше 12 лет назад

Integer overflow in the __tzfile_read function in glibc before 2.15 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted timezone (TZ) file, as demonstrated using vsftpd.

debian
больше 12 лет назад

Integer overflow in the __tzfile_read function in glibc before 2.15 al ...

github
больше 3 лет назад

Integer overflow in the __tzfile_read function in glibc before 2.15 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted timezone (TZ) file, as demonstrated using vsftpd.

oracle-oval
почти 14 лет назад

ELSA-2012-0058: glibc security and bug fix update (MODERATE)

EPSS

Процентиль: 86%
0.02765
Низкий

6.5 Medium

CVSS2