[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256610

 
 

909

 
 

199263

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2022-1857 --- glibc

ID: oval:org.secpod.oval:def:1701034Date: (C)2022-10-27   (M)2023-11-16
Class: PATCHFamily: unix




A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd may lead to memory corruption when the size of the buffer is exactly 1. A local attacker who can control the input buffer and size passed to getcwd in a setuid program could use this flaw to potentially execute arbitrary code and escalate their privileges on the system

Platform:
Amazon Linux 2
Product:
glibc
libcrypt
nscd
nss_db
nss_nis
nss_hesiod
Reference:
ALAS2-2022-1857
CVE-2021-3999
CVE    1
CVE-2021-3999

© SecPod Technologies