7.8

CVE-2017-1000366

glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these issues are not directly exploitable, as such they have not been given a CVE. This affects glibc 2.25 and earlier.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Enterprise Linux Version 5 Edition server
Redhat ≫ Enterprise Linux Version 6.0
Redhat ≫ Enterprise Linux Version 7.0
Novell ≫ Suse Linux Enterprise Desktop Version 12.0 Update sp2
Novell ≫ Suse Linux Enterprise Point Of Sale Version 11.0 Update sp3
Novell ≫ Suse Linux Enterprise Server Version 11.0 Update sp3 SwEdition ltss
Opensuse ≫ Leap Version 42.2
Suse ≫ Linux Enterprise For Sap Version 12 Update sp1
Suse ≫ Linux Enterprise Server Version 10 Update sp4 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 11 Update sp4
Suse ≫ Linux Enterprise Server Version 12 Update sp1 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 12 Update sp2
Suse ≫ Linux Enterprise Server Version 12 Update sp2 SwEdition ltss
Suse ≫ Linux Enterprise Software Development Kit Version 11.0 Update sp4
Suse ≫ Linux Enterprise Software Development Kit Version 12.0 Update sp2
Gnu ≫ Glibc Version <= 2.25
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Mcafee ≫ Web Gateway Version <= 7.6.2.14
Mcafee ≫ Web Gateway Version >= 7.7.0.0 <= 7.7.2.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.73% 0.842
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://packetstormsecurity.com/files/154361/Cisco-Device-Hardcoded-Credentials-GNU-glibc-BusyBox.html
http://seclists.org/fulldisclosure/2019/Sep/7
https://seclists.org/bugtraq/2019/Sep/7
https://security.gentoo.org/glsa/201706-19
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1567
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1712
Third Party Advisory
https://kc.mcafee.com/corporate/index?page=content&id=SB10205
Patch
Third Party Advisory
https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt
Third Party Advisory
Technical Description
https://www.suse.com/support/kb/doc/?id=7020973
Third Party Advisory
http://www.debian.org/security/2017/dsa-3887
Third Party Advisory
http://www.securityfocus.com/bid/99127
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1038712
Third Party Advisory
VDB Entry
https://access.redhat.com/errata/RHSA-2017:1479
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1480
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1481
Third Party Advisory
https://access.redhat.com/security/cve/CVE-2017-1000366
Third Party Advisory
https://www.exploit-db.com/exploits/42274/
Third Party Advisory
VDB Entry
https://www.exploit-db.com/exploits/42275/
Third Party Advisory
VDB Entry
https://www.exploit-db.com/exploits/42276/
Third Party Advisory
VDB Entry
https://www.suse.com/security/cve/CVE-2017-1000366/
Third Party Advisory