Wind River Support Network

HomeDefectsLIN7-9853
Fixed

LIN7-9853 : Security Advisory - glibc - CVE-2018-11236

Created: May 31, 2018    Updated: Oct 26, 2018
Resolved Date: Aug 14, 2018
Found In Version: 7.0.0.28
Fix Version: 7.0.0.29
Severity: Standard
Applicable for: Wind River Linux 7
Component/s: Toolchain

Description

stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures, leading to a stack-based buffer overflow and, potentially, arbitrary code execution.

https://nvd.nist.gov/vuln/detail/CVE-2018-11236

Other Downloads


CVEs


Live chat
Online