GNU glibc 'swscanf' Local Heap Buffer Overflow Vulnerability
BID:72428
Info
GNU glibc 'swscanf' Local Heap Buffer Overflow Vulnerability
| Bugtraq ID: | 72428 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2015-1472 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 21 2014 12:00AM |
| Updated: | Jul 05 2016 09:40PM |
| Credit: | Joseph Myers |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Oracle Linux 0 GNU glibc 2.12.2 GNU glibc 2.12.1 GNU glibc 2.11.2 GNU glibc 2.11.1 GNU glibc 2.10.1 GNU glibc 2.2.5 GNU glibc 2.2.4 GNU glibc 2.2.3 GNU glibc 2.2.2 GNU glibc 2.2.1 GNU glibc 2.2 GNU glibc 2.1.9 and Greater GNU glibc 2.1.9 GNU glibc 2.1.3 -10 GNU glibc 2.1.3 GNU glibc 2.1.2 GNU glibc 2.1.1 -6 GNU glibc 2.1.1 GNU glibc 2.1 GNU glibc 2.0.6 GNU glibc 2.0.5 GNU glibc 2.0.4 GNU glibc 2.0.3 GNU glibc 2.0.2 GNU glibc 2.0.1 GNU glibc 2.0 GNU glibc 2.14.1 GNU glibc 2.14 GNU glibc 2.13 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
GNU glibc 'swscanf' Local Heap Buffer Overflow Vulnerability
GNU glibc is prone to a heap-based buffer-overflow vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts may crash the application, denying service to legitimate users.
GNU glibc is prone to a heap-based buffer-overflow vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts may crash the application, denying service to legitimate users.
Exploit / POC
GNU glibc 'swscanf' Local Heap Buffer Overflow Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
GNU glibc 'swscanf' Local Heap Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
GNU glibc 'swscanf' Local Heap Buffer Overflow Vulnerability
References:
References:
- Bug 16618 - wscanf allocates too little memory (Bugzilla)
- GNU C Library Homepage (GNU)
- Critical: Vulnerabilities in the glibc are open that could lead to a local or re (IBM)
- isg3T1023385:Multiple vulnerabilities in the GNU C Library (glibc) affect PowerK (IBM)
- Multiple vulnerabilities in glibc affect IBM Flex System Manager(FSM) (CVE-2013- (IBM)
- pexip Security Bulletin: Multiple vulnerabilities (Pexip)
- Ref: linuxbulletinoct2015-2719645 Oracle Linux Bulletin - October 2015 Revision (Oracle)
- Security Bulletin: IBM BladeCenter Advanced Management Module is affected by gli (IBM)
- Security Bulletin: Multiple vulnerabilities in glibc affect IBM Flex System Mana (IBM)
- Security Bulletin: Vulnerabilities in GNU C Library affect Power Hardware Manage (IBM)
- Security Bulletin: Vulnerability in glibc affects IBM Security Virtual Server Pr (IBM)