Wind River Support Network

HomeDefectsLIN10-4050
Fixed

LIN10-4050 : Security Advisory - glibc - CVE-2018-11236

Created: May 31, 2018    Updated: Dec 3, 2018
Resolved Date: Jul 1, 2018
Found In Version: 10.17.41.1
Fix Version: 10.17.41.9
Severity: Standard
Applicable for: Wind River Linux LTS 17
Component/s: Toolchain

Description

stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures, leading to a stack-based buffer overflow and, potentially, arbitrary code execution.

https://nvd.nist.gov/vuln/detail/CVE-2018-11236

Other Downloads


CVEs


Live chat
Online