ZeroHour

CVE-2018-11236

CVSS 3.0
9.8 critical
EPSS
7%p94
Published
()
Modified
Description

stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures, leading to a stack-based buffer overflow and, potentially, arbitrary code execution.

Vendors
gnuredhatoraclenetapp
Products
glibc, virtualization host, enterprise linux desktop, enterprise linux server, enterprise linux workstation, communications session border controller, enterprise communications broker, data ontap edge, element software management
Weakness
CWE-190, CWE-787
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.