Wind River Support Network

HomeDefectsLIN8-9260
Fixed

LIN8-9260 : Security Advisory - glibc - CVE-2018-11236

Created: May 31, 2018    Updated: Dec 3, 2018
Resolved Date: Jun 29, 2018
Found In Version: 8.0.0.25
Fix Version: 8.0.0.27
Severity: Standard
Applicable for: Wind River Linux 8
Component/s: Toolchain

Description

stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures, leading to a stack-based buffer overflow and, potentially, arbitrary code execution.

https://nvd.nist.gov/vuln/detail/CVE-2018-11236

Other Downloads


CVEs


Live chat
Online