CVE-2014-9761
Summary
| CVE | CVE-2014-9761 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-04-19 21:59:00 UTC |
| Updated | 2019-06-13 21:29:00 UTC |
| Description | Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long argument to the (1) nan, (2) nanf, or (3) nanl function. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| [security-announce] SUSE-SU-2016:0470-1: important: Security update for |
SUSE |
lists.opensuse.org |
|
| Full Disclosure: SEC Consult SA-20190612-0 :: Multiple vulnerabilities in WAGO 852 Industrial Managed Switch Series |
FULLDISC |
seclists.org |
|
| oss-security - Re: CVE assignment request for security bugs fixed in glibc 2.23 |
MLIST |
www.openwall.com |
|
| 16962 – (CVE-2014-9761) nan function unbounded stack allocation (CVE-2014-9761) |
CONFIRM |
sourceware.org |
|
| Bugtraq: SEC Consult SA-20190612-0 :: Multiple vulnerabilities in WAGO 852 Industrial Managed Switch Series |
BUGTRAQ |
seclists.org |
|
| Adhemerval Zanella - The GNU C Library version 2.23 is now available |
MLIST |
www.sourceware.org |
Vendor Advisory |
| USN-2985-2: GNU C Library regression | Ubuntu |
UBUNTU |
www.ubuntu.com |
|
| Full Disclosure: SEC Consult SA-20190904-0 :: Multiple vulnerabilities in Cisco router series RV34X, RV26X and RV16X |
FULLDISC |
seclists.org |
|
| oss-security - CVE assignment request for security bugs fixed in glibc 2.23 |
MLIST |
www.openwall.com |
|
| Cisco Device Hardcoded Credentials / GNU glibc / BusyBox ≈ Packet Storm |
MISC |
packetstormsecurity.com |
|
| [security-announce] SUSE-SU-2016:0472-1: important: Security update for |
SUSE |
lists.opensuse.org |
|
| Bugtraq: SEC Consult SA-20190904-0 :: Multiple vulnerabilities in Cisco router series RV34X, RV26X and RV16X |
BUGTRAQ |
seclists.org |
|
| [security-announce] SUSE-SU-2016:0473-1: important: Security update for |
SUSE |
lists.opensuse.org |
|
| [security-announce] openSUSE-SU-2016:0510-1: important: Security update |
SUSE |
lists.opensuse.org |
|
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
|
| [SECURITY] Fedora 23 Update: glibc-2.22-15.fc23 |
FEDORA |
lists.fedoraproject.org |
|
| USN-2985-1: GNU C Library vulnerabilities | Ubuntu |
UBUNTU |
www.ubuntu.com |
|
| [security-announce] SUSE-SU-2016:0471-1: important: Security update for |
SUSE |
lists.opensuse.org |
|
| GNU C Library: Multiple vulnerabilities (GLSA 201702-11) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| GNU glibc CVE-2014-9761 Stack Buffer Overflow Vulnerability |
BID |
www.securityfocus.com |
|
| WAGO 852 Industrial Managed Switch Series Code Execution / Hardcoded Credentials ≈ Packet Storm |
MISC |
packetstormsecurity.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710558 Gentoo Linux GNU C Library Multiple Vulnerabilities (GLSA 201702-11)