OpenBSD libc glob 'GLOB_APPEND' and 'GLOB_DOOFFS' Flags Multiple Integer Overflow Vulnerabilities
BID:48004
Info
OpenBSD libc glob 'GLOB_APPEND' and 'GLOB_DOOFFS' Flags Multiple Integer Overflow Vulnerabilities
| Bugtraq ID: | 48004 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2011-2168 |
| Remote: | Yes |
| Local: | Yes |
| Published: | May 26 2011 12:00AM |
| Updated: | May 26 2011 12:00AM |
| Credit: | OpenBSD |
| Vulnerable: |
OpenBSD OpenBSD 4.7 OpenBSD OpenBSD 4.6 OpenBSD OpenBSD 4.5 OpenBSD OpenBSD 4.4 OpenBSD OpenBSD 4.3 OpenBSD OpenBSD 4.2 OpenBSD OpenBSD 4.1 OpenBSD OpenBSD 4.0 OpenBSD libc 0 |
| Not Vulnerable: | |
Discussion
OpenBSD libc glob 'GLOB_APPEND' and 'GLOB_DOOFFS' Flags Multiple Integer Overflow Vulnerabilities
libc in OpenBSD is prone to multiple integer-overflow vulnerabilities.
The attacker can exploit these issues to execute arbitrary code with the privileges of the application using the affected library. Failed exploit attempts will result in a denial-of-service condition.
libc in OpenBSD is prone to multiple integer-overflow vulnerabilities.
The attacker can exploit these issues to execute arbitrary code with the privileges of the application using the affected library. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
OpenBSD libc glob 'GLOB_APPEND' and 'GLOB_DOOFFS' Flags Multiple Integer Overflow Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
OpenBSD libc glob 'GLOB_APPEND' and 'GLOB_DOOFFS' Flags Multiple Integer Overflow Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
OpenBSD libc glob 'GLOB_APPEND' and 'GLOB_DOOFFS' Flags Multiple Integer Overflow Vulnerabilities
References:
References:
- CVS log for src/lib/libc/gen/glob.c (OpenBSD)
- OpenBSD Homepage (OpenBSD)