RETIRED: GNU glibc 'strcoll()' Routine Stack Buffer Overflow Vulnerability
BID:72603
Info
RETIRED: GNU glibc 'strcoll()' Routine Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 72603 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 13 2015 12:00AM |
| Updated: | Mar 07 2017 12:07AM |
| Credit: | Shaun Colley |
| Vulnerable: |
GNU glibc 2.12.2 GNU glibc 2.12.1 GNU glibc 2.11.2 GNU glibc 2.11.1 GNU glibc 2.10.1 GNU glibc 2.20 GNU glibc 2.19 GNU glibc 2.18 GNU glibc 2.17 GNU glibc 2.16 GNU glibc 2.15 GNU glibc 2.14.1 GNU glibc 2.14 GNU glibc 2.13 GNU glibc 2.12 GNU glibc 2.11.3 GNU glibc 2.11 |
| Not Vulnerable: |
GNU glibc 2.21 |
Discussion
RETIRED: GNU glibc 'strcoll()' Routine Stack Buffer Overflow Vulnerability
GNU glibc is prone to a stack-based buffer-overflow vulnerability.
Successful exploits may allow an attacker to execute arbitrary code in the context of a user running an application that uses the affected library. Failed exploit attempts may crash the application, denying service to legitimate users.
glibc 2.3 through versions prior to 2.21 are vulnerable.
Note : This BID is being retired as it is a duplicate of BID 72602 (GNU glibc 'strxfrm()' Function Local Integer Overflow and Stack Overflow Vulnerabilities)
GNU glibc is prone to a stack-based buffer-overflow vulnerability.
Successful exploits may allow an attacker to execute arbitrary code in the context of a user running an application that uses the affected library. Failed exploit attempts may crash the application, denying service to legitimate users.
glibc 2.3 through versions prior to 2.21 are vulnerable.
Note : This BID is being retired as it is a duplicate of BID 72602 (GNU glibc 'strxfrm()' Function Local Integer Overflow and Stack Overflow Vulnerabilities)
Exploit / POC
RETIRED: GNU glibc 'strcoll()' Routine Stack Buffer Overflow Vulnerability
An attacker can exploit this issue using readily available commands and tools.
An attacker can exploit this issue using readily available commands and tools.
Solution / Fix
RETIRED: GNU glibc 'strcoll()' Routine Stack Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
RETIRED: GNU glibc 'strcoll()' Routine Stack Buffer Overflow Vulnerability
References:
References:
- Bug 16009 - Possible buffer overflow in strxfrm (Sourceware)
- Fix memory handling in strxfrm_l [BZ #16009] (Sourceware)
- GNU C Library Homepage (GNU)