[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256288

 
 

909

 
 

199146

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2023-2023-060 --- glibc

ID: oval:org.secpod.oval:def:19500147Date: (C)2023-06-12   (M)2023-06-12
Class: PATCHFamily: unix




A stack based buffer-overflow vulnerability was found in the deprecated compatibility function clnt_create in the sunrpc's clnt_gen.c module of the GNU C Library through 2.34. This vulnerability copies its hostname argument onto the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or lead to arbitrary code execution

Platform:
Amazon Linux 2023
Product:
glibc
nss_db
nscd
nss_hesiod
libnsl
compat-libpthread-nonshared
sysroot-x86_64-fc34-glibc
sysroot-i386-fc34-glibc
sysroot-aarch64-fc34-glibc
Reference:
ALAS2023-2023-060
CVE-2022-23219
CVE    1
CVE-2022-23219
CPE    6
cpe:/a:compat-libpthread-nonshared:compat-libpthread-nonshared
cpe:/a:glibc:glibc
cpe:/a:piotr_roszatycki:nss-db
cpe:/a:libnsl:libnsl
...

© SecPod Technologies