漏洞信息详情
GNU C Library 资源管理错误漏洞
漏洞简介
GNU C Library(glibc,libc6)是一种按照LGPL许可协议发布的开源免费的C语言编译程序。
GNU C Library (aka glibc or libc6) 2.29 through 2.33 存在资源管理错误漏洞,该漏洞源于缓存守护进程(nscd)在处理网络组查找请求时,可能会由于双free而崩溃。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://sourceware.org/bugzilla/show_bug.cgi?id=27462
参考网址
来源:MISC
链接:https://sourceware.org/bugzilla/show_bug.cgi?id=27462
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/I7TS26LIZSOBLGJEZMJX4PXT5BQDE2WS/
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/7LZNT6KTMCCWPWXEOGSHD3YLYZKUGMH5/
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021070604
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/glibc-use-after-free-via-nscd-35508
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3785
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/165096/Red-Hat-Security-Advisory-2021-4845-05.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3935
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2021-27645
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163406/Gentoo-Linux-Security-Advisory-202107-07.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3905
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.4019
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164863/Red-Hat-Security-Advisory-2021-4358-03.html
来源:access.redhat.com
链接:https://access.redhat.com/security/cve/cve-2021-27645
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/165002/Red-Hat-Security-Advisory-2021-4032-01.html
受影响实体
暂无
补丁
- GNU C Library(aka glibc or libc) through 资源管理错误漏洞的修复措施<!--2021-2-24-->
还没有评论,来说两句吧...