Wind River Support Network

HomeDefectsLIN1018-6959
Fixed

LIN1018-6959 : Security Advisory - glibc - CVE-2020-29573

Created: Dec 6, 2020    Updated: Mar 5, 2021
Resolved Date: Mar 5, 2021
Found In Version: 10.18.44.1
Severity: Standard
Applicable for: Wind River Linux LTS 18
Component/s: Userspace

Description

sysdeps/i386/ldbl2mpn.c in the GNU C Library (aka glibc or libc6) before 2.23 on x86 targets has a stack-based buffer overflow if the input to any of the printf family of functions is an 80-bit long double with a non-canonical bit pattern, as seen when passing a \x00\x04\x00\x00\x00\x00\x00\x00\x00\x04 value to sprintf.

CREATE(Triage):(User=admin) [CVE-2020-29573|https://nvd.nist.gov/vuln/detail/CVE-2020-29573]

CVEs


Live chat
Online