CVE-2020-6096
Summary
| CVE | CVE-2020-6096 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-01 22:15:00 UTC |
| Updated | 2023-11-07 03:24:00 UTC |
| Description | An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) with a negative value for the 'num' parameter results in a signed comparison vulnerability. If an attacker underflows the 'num' parameter to memcpy(), this vulnerability could lead to undefined behavior such as writing to out-of-bounds memory and potentially remote code execution. Furthermore, this memcpy() implementation allows for program execution to continue in scenarios where a segmentation fault or crash should have occurred. The dangers occur in that subsequent execution and iterations of this code will be executed with this corrupted data. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Pony Mail! |
MLIST |
lists.apache.org |
Mailing List, Third Party Advisory |
| [SECURITY] Fedora 31 Update: glibc-2.30-13.fc31 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| 25620 – (CVE-2020-6096) Signed comparison vulnerability in the ARMv7 memcpy() (CVE-2020-6096) |
MISC |
sourceware.org |
Issue Tracking, Third Party Advisory |
| TALOS-2020-1019 || Cisco Talos Intelligence Group - Comprehensive Threat Intelligence |
MISC |
www.talosintelligence.com |
Third Party Advisory |
| glibc: Multiple vulnerabilities (GLSA 202101-20) — Gentoo security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| [SECURITY] [DLA 3152-1] glibc security update |
MLIST |
lists.debian.org |
|
| [SECURITY] Fedora 32 Update: glibc-2.31-4.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 31 Update: glibc-2.30-13.fc31 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| [mina-dev] 20210225 [jira] [Created] (FTPSERVER-500) Security vulnerability in common/lib/log4j-1.2.17.jar |
|
lists.apache.org |
|
| [SECURITY] Fedora 32 Update: glibc-2.31-4.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181138 Debian Security Update for glibc (DLA 3152-1)
- 198685 Ubuntu Security Notification for GNU C Library Vulnerabilities (USN-5310-1)
- 377356 Alibaba Cloud Linux Security Update for glibc (ALINUX3-SA-2022:0122)
- 900018 CBL-Mariner Linux Security Update for glibc 2.28
- 902894 Common Base Linux Mariner (CBL-Mariner) Security Update for glibc (2553)
- 905858 Common Base Linux Mariner (CBL-Mariner) Security Update for glibc (2553-1)