Wind River Support Network

HomeDefectsLIN9-6933
Fixed

LIN9-6933 : Security Advisory - glibc - CVE-2018-11236

Created: May 31, 2018    Updated: Dec 3, 2018
Resolved Date: Jul 5, 2018
Found In Version: 9.0.0.15
Fix Version: 9.0.0.17
Severity: Standard
Applicable for: Wind River Linux 9
Component/s: Toolchain

Description

stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures, leading to a stack-based buffer overflow and, potentially, arbitrary code execution.

https://nvd.nist.gov/vuln/detail/CVE-2018-11236

Other Downloads


CVEs


Live chat
Online