CVE-2007-3508
Summary
| CVE | CVE-2007-3508 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-07-03 21:30:00 UTC |
| Updated | 2023-11-07 02:00:00 UTC |
| Description | ** DISPUTED ** Integer overflow in the process_envvars function in elf/rtld.c in glibc before 2.5-rc4 might allow local users to execute arbitrary code via a large LD_HWCAP_MASK environment variable value. NOTE: the glibc maintainers state that they do not believe that this issue is exploitable for code execution. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Gentoo |
Glibc |
All |
r3 |
All |
All |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|
| Mandriva | 2007-09-17 | Vincent Danen | Based on the analysis of Red Hat and several Glibc developers, Mandriva does not believe this to be exploitable. |
| Red Hat | 2007-07-05 | Joshua Bressers | After careful analysis by Red Hat and several Glibc developers, it has been determined that this bug is not exploitable. For more information please see Red Hat Bugzilla bug #247208 https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=247208 |
There are currently no legacy QID mappings associated with this CVE.