6.8

CVE-2009-5029

Exploit
Integer overflow in the __tzfile_read function in glibc before 2.15 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted timezone (TZ) file, as demonstrated using vsftpd.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gnu ≫ Glibc Version <= 2.14
Gnu ≫ Glibc Version 2.0
Gnu ≫ Glibc Version 2.0.1
Gnu ≫ Glibc Version 2.0.2
Gnu ≫ Glibc Version 2.0.3
Gnu ≫ Glibc Version 2.0.4
Gnu ≫ Glibc Version 2.0.5
Gnu ≫ Glibc Version 2.0.6
Gnu ≫ Glibc Version 2.1
Gnu ≫ Glibc Version 2.1.1
Gnu ≫ Glibc Version 2.1.1.6
Gnu ≫ Glibc Version 2.1.2
Gnu ≫ Glibc Version 2.1.3
Gnu ≫ Glibc Version 2.1.9
Gnu ≫ Glibc Version 2.13
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.07% 0.941
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://dividead.wordpress.com/2009/06/01/glibc-timezone-integer-overflow/
Exploit
http://lists.grok.org.uk/pipermail/full-disclosure/2011-December/084452.html
http://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=97ac2654b2d831acaa18a2b018b0736245903fd2
http://sourceware.org/ml/libc-alpha/2011-12/msg00037.html
Exploit
https://bugzilla.redhat.com/show_bug.cgi?id=761245