[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2020-1751Date: (C)2020-04-20   (M)2024-04-17


An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtrace function did not properly check the array bounds when storing the frame address, resulting in a denial of service or potential code execution. The highest threat from this vulnerability is to system availability.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 7.0CVSS Score : 5.9
Exploit Score: 1.0Exploit Score: 3.4
Impact Score: 5.9Impact Score: 8.5
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: LOCALAccess Vector: LOCAL
Attack Complexity: HIGHAccess Complexity: MEDIUM
Privileges Required: LOWAuthentication: NONE
User Interaction: NONEConfidentiality: PARTIAL
Scope: UNCHANGEDIntegrity: PARTIAL
Confidentiality: HIGHAvailability: COMPLETE
Integrity: HIGH 
Availability: HIGH 
  
Reference:
GLSA-202006-04
USN-4416-1
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1751
https://security.netapp.com/advisory/ntap-20200430-0002/
https://sourceware.org/bugzilla/show_bug.cgi?id=25423

CPE    2
cpe:/a:gnu:glibc
cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~
CWE    1
CWE-787
OVAL    10
oval:org.secpod.oval:def:64136
oval:org.secpod.oval:def:64137
oval:org.secpod.oval:def:67958
oval:org.secpod.oval:def:117986
...

© SecPod Technologies