GNU glibc 'strxfrm()' Function Local Integer Overflow and Stack Overflow Vulnerabilities
BID:72602
Info
GNU glibc 'strxfrm()' Function Local Integer Overflow and Stack Overflow Vulnerabilities
| Bugtraq ID: | 72602 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2015-8982 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 13 2015 12:00AM |
| Updated: | Mar 29 2017 02:01AM |
| Credit: | Joseph Myers |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 GNU glibc2 2.3.10 GNU glibc 2.12.2 GNU glibc 2.12.1 GNU glibc 2.11.2 GNU glibc 2.11.1 GNU glibc 2.10.1 GNU glibc 2.5 GNU glibc 2.3.10 GNU glibc 2.3.4 GNU glibc 2.3.3 GNU glibc 2.3.2 GNU glibc 2.3.1 GNU glibc 2.3 GNU glibc 2.9 GNU glibc 2.8 GNU glibc 2.7 GNU glibc 2.6.1 GNU glibc 2.6 GNU glibc 2.5.1 GNU glibc 2.4 GNU glibc 2.3.6 GNU glibc 2.3.5 GNU glibc 2.20 GNU glibc 2.19 GNU glibc 2.18 GNU glibc 2.17 GNU glibc 2.16 GNU glibc 2.15 GNU glibc 2.14.1 GNU glibc 2.14 GNU glibc 2.13 GNU glibc 2.12 GNU glibc 2.11.3 GNU glibc 2.11 |
| Not Vulnerable: |
GNU glibc 2.21 |
Discussion
GNU glibc 'strxfrm()' Function Local Integer Overflow and Stack Overflow Vulnerabilities
GNU glibc is prone to a local integer-overflow vulnerability and a local stack-based buffer-overflow vulnerability
Successful exploits may allow an attacker to execute arbitrary code in the context of a user running an application that uses the affected library. Failed exploit attempts may crash the application, denying service to legitimate users.
glibc 2.3 through versions prior to 2.21 are vulnerable.
Note: This issue was previously titled 'GNU glibc 'strxfrm()' Routine Integer Overflow Vulnerability'. The title have been changed to better document it.
GNU glibc is prone to a local integer-overflow vulnerability and a local stack-based buffer-overflow vulnerability
Successful exploits may allow an attacker to execute arbitrary code in the context of a user running an application that uses the affected library. Failed exploit attempts may crash the application, denying service to legitimate users.
glibc 2.3 through versions prior to 2.21 are vulnerable.
Note: This issue was previously titled 'GNU glibc 'strxfrm()' Routine Integer Overflow Vulnerability'. The title have been changed to better document it.
Exploit / POC
GNU glibc 'strxfrm()' Function Local Integer Overflow and Stack Overflow Vulnerabilities
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
Solution / Fix
GNU glibc 'strxfrm()' Function Local Integer Overflow and Stack Overflow Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
GNU glibc 'strxfrm()' Function Local Integer Overflow and Stack Overflow Vulnerabilities
References:
References:
- Bug 16009 - Possible buffer overflow in strxfrm (Sourceware)
- Fix memory handling in strxfrm_l [BZ #16009] (Sourceware)
- glibc: multiple overflows in strxfrm() (Red Hat)
- GNU C Library Homepage (GNU)