LWN.net Logo

glibc: code execution

Package(s):glibc CVE #(s):CVE-2012-3480
Created:August 20, 2012 Updated:August 28, 2012
Description: From the Red Hat bugzilla:

Multiple integer overflows, leading to stack-based buffer overflows were found in various stdlib functions of GNU libc (strtod, strtof, strtold, strtod_l and related routines). If an application, using the affected stdlib functions, did not perform user-level sanitization of provided inputs, a local attacker could use this flaw to cause such an application to crash or, potentially, execute arbitrary code with the privileges of the user running the application.

Alerts:
Fedora FEDORA-2012-11927 2012-08-18
Red Hat RHSA-2012:1208-01 2012-08-27
Red Hat RHSA-2012:1207-01 2012-08-27
CentOS CESA-2012:1207 2012-08-27
CentOS CESA-2012:1208 2012-08-27
Fedora FEDORA-2012-11928 2012-08-27
Oracle ELSA-2012-1208 2012-08-27
Oracle ELSA-2012-1207 2012-08-27
Scientific Linux SL-glib-20120827 2012-08-27
Scientific Linux SL-glib-20120827 2012-08-27
Ubuntu USN-1589-1 2012-10-01
Ubuntu USN-1589-2 2012-12-17
Mandriva MDVSA-2013:162 2013-05-07

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds