GNU glibc Multiple Local Stack Buffer Overflow Vulnerabilities
BID:54982
Info
GNU glibc Multiple Local Stack Buffer Overflow Vulnerabilities
| Bugtraq ID: | 54982 |
| Class: | Design Error |
| CVE: |
CVE-2012-3480 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 13 2012 12:00AM |
| Updated: | Apr 13 2015 09:34PM |
| Credit: | Joseph S. Myer |
| Vulnerable: |
VMWare ESXi 4.1 VMWare ESXi 4.0 VMWare ESXi 3.5 VMWare ESX 4.1 VMWare ESX 4.0 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Slackware Linux x86_64 -current Slackware Linux 13.37 x86_64 Slackware Linux 13.37 Slackware Linux 13.1 x86_64 Slackware Linux 13.1 Slackware Linux -current RedHat Enterprise Linux 5.0 Red Hat Enterprise Virtualization Hypervisor for RHEL 6 0 Red Hat Enterprise Virtualization Hypervisor for RHEL 5 0 Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 6 Red Hat Enterprise Linux 5 Server Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Gentoo Linux Avaya Voice Portal 5.1.2 Avaya Voice Portal 5.1.1 Avaya Voice Portal 5.1 SP1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.0 SP2 Avaya Voice Portal 5.0 SP1 Avaya Voice Portal 5.0 Avaya Proactive Contact 5.0 Avaya IQ 5.2 Avaya IQ 5.1.1 Avaya IQ 5.1 Avaya IQ 5 Avaya IP Office Application Server 8.1 Avaya IP Office Application Server 8.0 Avaya Conferencing Standard Edition 6.0 SP1 Avaya Conferencing Standard Edition 6.0 Avaya Communication Server 1000M Signaling Server 7.5 Avaya Communication Server 1000M Signaling Server 7.0 Avaya Communication Server 1000M Signaling Server 6.0 Avaya Communication Server 1000M 7.5 Avaya Communication Server 1000M 7.0 Avaya Communication Server 1000M 6.0 Avaya Communication Server 1000E Signaling Server 7.5 Avaya Communication Server 1000E Signaling Server 7.0 Avaya Communication Server 1000E Signaling Server 6.0 Avaya Communication Server 1000E 7.5 Avaya Communication Server 1000E 7.0 Avaya Communication Server 1000E 6.0 Avaya Aura System Platform 6.0.2 Avaya Aura System Platform 6.0.1 Avaya Aura System Platform 6.0 SP3 Avaya Aura System Platform 6.0 SP2 Avaya Aura System Platform 6.0 Avaya Aura System Platform 1.1 Avaya Aura System Manager 6.2 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 SP2 Avaya Aura System Manager 6.1 Sp1 Avaya Aura System Manager 6.1 Avaya Aura System Manager 6.0 SP1 Avaya Aura System Manager 6.0 Avaya Aura System Manager 5.2 Avaya Aura Session Manager 6.2.1 Avaya Aura Session Manager 6.1.3 Avaya Aura Session Manager 6.1.2 Avaya Aura Session Manager 6.1.1 Avaya Aura Session Manager 6.2 Avaya Aura Session Manager 6.1 SP2 Avaya Aura Session Manager 6.1 Sp1 Avaya Aura Session Manager 6.1 Avaya Aura Session Manager 6.0 SP1 Avaya Aura Session Manager 6.0 Avaya Aura Session Manager 5.2 SP2 Avaya Aura Session Manager 5.2 SP1 Avaya Aura Session Manager 5.2 Avaya Aura Session Manager 1.1 Avaya Aura Session Manager 1.0 Avaya Aura Presence Services 6.1.1 Avaya Aura Presence Services 6.0 Avaya Aura Messaging 6.1 Avaya Aura Messaging 6.0.1 Avaya Aura Messaging 6.0 Avaya Aura Experience Portal 6.0 Avaya Aura Communication Manager Utility Services 6.2 Avaya Aura Communication Manager Utility Services 6.1 Avaya Aura Communication Manager Utility Services 6.0 Avaya Aura Communication Manager 6.0.1 Avaya Aura Communication Manager 6.0 Avaya Aura Application Server 5300 SIP Core 2.1 Avaya Aura Application Server 5300 SIP Core 2.0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 6.1.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 5.2.3 Avaya Aura Application Enablement Services 5.2.2 Avaya Aura Application Enablement Services 5.2 |
| Not Vulnerable: | |
Discussion
GNU glibc Multiple Local Stack Buffer Overflow Vulnerabilities
GNU glibc is prone to multiple stack-based buffer-overflow vulnerabilities because it fails to perform adequate boundary checks on user-supplied data.
Local attackers can exploit these issues to run arbitrary code with privileges of the affected application. Failed exploit attempts can result in a denial-of-service condition.
GNU glibc is prone to multiple stack-based buffer-overflow vulnerabilities because it fails to perform adequate boundary checks on user-supplied data.
Local attackers can exploit these issues to run arbitrary code with privileges of the affected application. Failed exploit attempts can result in a denial-of-service condition.
Exploit / POC
GNU glibc Multiple Local Stack Buffer Overflow Vulnerabilities
The following example exploit is available:
The following example exploit is available:
Solution / Fix
GNU glibc Multiple Local Stack Buffer Overflow Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Slackware Linux 13.1
Slackware Linux x86_64 -current
MandrakeSoft Enterprise Server 5
Slackware Linux 13.37
Solution:
Updates are available. Please see the references for more information.
Slackware Linux 13.1
-
Slackware glibc-2.11.1-i486-7_slack13.1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/ glibc-2.11.1-i486-7_slack13.1.txz -
Slackware glibc-i18n-2.11.1-i486-7_slack13.1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/ glibc-i18n-2.11.1-i486-7_slack13.1.txz -
Slackware glibc-profile-2.11.1-i486-7_slack13.1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/ glibc-profile-2.11.1-i486-7_slack13.1.txz -
Slackware glibc-solibs-2.11.1-i486-7_slack13.1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/ glibc-solibs-2.11.1-i486-7_slack13.1.txz -
Slackware glibc-zoneinfo-2.11.1-noarch-7_slack13.1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/ glibc-zoneinfo-2.11.1-noarch-7_slack13.1.txz
Slackware Linux x86_64 -current
-
Slackware glibc-2.15-x86_64-6.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/ l/glibc-2.15-x86_64-6.txz -
Slackware glibc-i18n-2.15-x86_64-6.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/ l/glibc-i18n-2.15-x86_64-6.txz -
Slackware glibc-profile-2.15-x86_64-6.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/ l/glibc-profile-2.15-x86_64-6.txz -
Slackware glibc-solibs-2.15-x86_64-6.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/ a/glibc-solibs-2.15-x86_64-6.txz
MandrakeSoft Enterprise Server 5
-
Mandriva glibc-2.8-1.20080520.5.9mnb2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva glibc-devel-2.8-1.20080520.5.9mnb2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva glibc-doc-2.8-1.20080520.5.9mnb2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva glibc-doc-pdf-2.8-1.20080520.5.9mnb2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva glibc-i18ndata-2.8-1.20080520.5.9mnb2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva glibc-profile-2.8-1.20080520.5.9mnb2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva glibc-static-devel-2.8-1.20080520.5.9mnb2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva glibc-utils-2.8-1.20080520.5.9mnb2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva nscd-2.8-1.20080520.5.9mnb2.i586.rpm
http://www.mandriva.com/en/downloads/
Slackware Linux 13.37
-
Slackware glibc-2.13-i486-6_slack13.37.txz
ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages /glibc-2.13-i486-6_slack13.37.txz -
Slackware glibc-i18n-2.13-i486-6_slack13.37.txz
ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages /glibc-i18n-2.13-i486-6_slack13.37.txz -
Slackware glibc-profile-2.13-i486-6_slack13.37.txz
ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages /glibc-profile-2.13-i486-6_slack13.37.txz -
Slackware glibc-solibs-2.13-i486-6_slack13.37.txz
ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages /glibc-solibs-2.13-i486-6_slack13.37.txz -
Slackware glibc-zoneinfo-2.13-noarch-6_slack13.37.txz
ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages /glibc-zoneinfo-2.13-noarch-6_slack13.37.txz
References
GNU glibc Multiple Local Stack Buffer Overflow Vulnerabilities
References:
References: