glibc '__fortify_fail()' Function Local Information Disclosure Vulnerability
BID:44112
Info
glibc '__fortify_fail()' Function Local Information Disclosure Vulnerability
| Bugtraq ID: | 44112 |
| Class: | Design Error |
| CVE: |
CVE-2010-3192 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 27 2010 12:00AM |
| Updated: | Apr 27 2010 12:00AM |
| Credit: | Dan Rosenberg |
| Vulnerable: |
GNU glibc 0 |
| Not Vulnerable: | |
Discussion
glibc '__fortify_fail()' Function Local Information Disclosure Vulnerability
The glibc library is prone to a local information-disclosure vulnerability.
Successful exploits may allow local attackers to obtain potentially sensitive information from the address space of the programs that may aid in other attacks.
The glibc library is prone to a local information-disclosure vulnerability.
Successful exploits may allow local attackers to obtain potentially sensitive information from the address space of the programs that may aid in other attacks.
Exploit / POC
glibc '__fortify_fail()' Function Local Information Disclosure Vulnerability
An attacker requires local interactive access to exploit this issue.
An attacker requires local interactive access to exploit this issue.
Solution / Fix
glibc '__fortify_fail()' Function Local Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
glibc '__fortify_fail()' Function Local Information Disclosure Vulnerability
References:
References:
- Bug Discussion Thread (oss-security)
- Fun with FORTIFY_SOURCE (Dan Rosenberg)
- glibc Homepage (GNU)