Glibc文件通配符堆损坏漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1204984 漏洞类型 缓冲区溢出
发布时间 2001-12-21 更新时间 2005-10-12
CVE编号 CVE-2001-0886 CNNVD-ID CNNVD-200112-128
漏洞平台 N/A CVSS评分 4.6
|漏洞来源
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200112-128
|漏洞详情
glibc的glob函数存在缓冲区溢出漏洞。攻击者借助以大括号“{”字符结束的glob模式导致服务拒绝(崩溃)且可能执行任意代码。
|参考资料
resource:
hyperlink:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000447
resource:
hyperlink:http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-037-01
resource:
hyperlink:http://sources.redhat.com/ml/bug-glibc/2001-11/msg00109.html
resource:
hyperlink:http://www.ciac.org/ciac/bulletins/m-029.shtml
resource:
hyperlink:http://www.debian.org/security/2002/dsa-103
resource:
hyperlink:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-095.php3
resource:
hyperlink:http://www.linuxsecurity.com/advisories/other_advisory-1752.html
resource:Patch
hyperlink:http://www.redhat.com/support/errata/RHSA-2001-160.html
resource:
hyperlink:http://www.securityfocus.com/archive/1/245956
resource:
hyperlink:http://www.securityfocus.com/bid/3707
resource:
hyperlink:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBTL0112-008
resource:
hyperlink:https://exchange.xforce.ibmcloud.com/vulnerabilities/7705