[Forgot Password]
Login  Register Subscribe

24128

 
 

131615

 
 

111666

 
 

909

 
 

87321

 
 

136

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML view JSON

CVE-2012-2673Date: (C)2012-07-25   (M)2018-06-02


Multiple integer overflows in the (1) GC_generic_malloc and (2) calloc functions in malloc.c, and the (3) GC_generic_malloc_ignore_off_page function in mallocx.c in Boehm-Demers-Weiser GC (libgc) before 7.2 make it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large size value, which causes less memory to be allocated than expected.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
BID-54227
FEDORA-2012-9556
FEDORA-2012-9637
MDVSA-2012:158
RHSA-2013:1500
RHSA-2014:0149
RHSA-2014:0150
USN-1546-1
http://www.openwall.com/lists/oss-security/2012/06/05/1
http://www.openwall.com/lists/oss-security/2012/06/07/13
http://kqueue.org/blog/2012/03/05/memory-allocator-security-revisited/
https://github.com/ivmai/bdwgc/blob/master/ChangeLog
https://github.com/ivmai/bdwgc/commit/6a93f8e5bcad22137f41b6c60a1c7384baaec2b3
https://github.com/ivmai/bdwgc/commit/83231d0ab5ed60015797c3d1ad9056295ac3b2bb
https://github.com/ivmai/bdwgc/commit/be9df82919960214ee4b9d3313523bff44fd99e1
https://github.com/ivmai/bdwgc/commit/e10c1eb9908c2774c16b3148b30d2f3823d66a9a

CPE    95
cpe:/a:boehm-demers-weiser:garbage_collector:4.2
cpe:/a:boehm-demers-weiser:garbage_collector:4.1
cpe:/a:boehm-demers-weiser:garbage_collector:4.4
cpe:/a:boehm-demers-weiser:garbage_collector:4.3
...
CWE    1
CWE-189
OVAL    9
oval:org.secpod.oval:def:1600324
oval:org.secpod.oval:def:501129
oval:org.secpod.oval:def:1500288
oval:org.secpod.oval:def:202956
...

© SecPod Technologies