[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2022-1576 --- glibc

ID: oval:org.secpod.oval:def:1601527Date: (C)2022-04-08   (M)2023-01-09
Class: PATCHFamily: unix




A stack based buffer-overflow vulnerability was found in the deprecated compatibility function svcunix_create in the sunrpc' svc_unix.c module of the GNU C Library through 2.34. This vulnerability copies its path argument onto the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or then it will lead to arbitrary code execution. A stack based buffer-overflow vulnerability was found in the deprecated compatibility function clnt_create in the sunrpc' clnt_gen.c module of the GNU C Library through 2.34. This vulnerability copies its hostname argument onto the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or lead to arbitrary code execution

Platform:
Amazon Linux AMI
Product:
glibc
nscd
Reference:
ALAS-2022-1576
CVE-2022-23218
CVE-2022-23219
CVE    2
CVE-2022-23218
CVE-2022-23219

© SecPod Technologies