漏洞信息详情
GNU glibc 基于栈的缓冲区溢出漏洞
漏洞简介
GNU C Library(又名glibc,libc6)是一种按照LGPL许可协议发布的开源免费的C语言编译程序。
GNU C Library 2.23之前版本中存在基于栈的缓冲区溢出漏洞。攻击者可借助‘nan’、‘nanf’或‘nanl’函数的较长的参数利用该漏洞造成拒绝服务(应用程序崩溃),或执行任意代码。
漏洞公告
目前厂商已经发布了升级补丁以修复此安全问题,详情请关注厂商主页:
http://www.gnu.org/software/libc/
参考网址
来源:MISC
链接:http://packetstormsecurity.com/files/153278/WAGO-852-Industrial-Managed-Switch-Series-Code-Execution-Hardcoded-Credentials.html
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00037.html
来源:REDHAT
链接:http://rhn.redhat.com/errata/RHSA-2017-0680.html
来源:FULLDISC
链接:http://seclists.org/fulldisclosure/2019/Jun/18
来源:MLIST
链接:http://www.openwall.com/lists/oss-security/2016/01/19/11
来源:UBUNTU
链接:http://www.ubuntu.com/usn/USN-2985-2
来源:UBUNTU
链接:http://www.ubuntu.com/usn/USN-2985-1
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2017:1916
来源:FEDORA
链接:http://lists.fedoraproject.org/pipermail/package-announce/2016-May/184626.html
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00038.html
来源:BUGTRAQ
链接:https://seclists.org/bugtraq/2019/Jun/14
来源:GENTOO
链接:https://security.gentoo.org/glsa/201702-11
来源:CONFIRM
链接:https://sourceware.org/bugzilla/show_bug.cgi?id=16962
来源:MLIST
链接:https://www.sourceware.org/ml/libc-alpha/2016-02/msg00502.html
来源:BID
链接:https://www.securityfocus.com/bid/83306
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00036.html
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00042.html
来源:MLIST
链接:http://www.openwall.com/lists/oss-security/2016/01/20/1
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00039.html
来源:www.ibm.com
链接:http://www.ibm.com/support/docview.wss
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/76426
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/154361/Cisco-Device-Hardcoded-Credentials-GNU-glibc-BusyBox.html
受影响实体
- Fedoraproject Fedora:23<!--2000-1-1-->
- Suse Linux_enterprise_debuginfo:11.0:Sp3<!--2000-1-1-->
补丁
- GNU glibc 基于栈的缓冲区溢出漏洞的修复措施<!--2016-2-26-->
还没有评论,来说两句吧...