CVE-1999-0199
published 2020-10-06CVE-1999-0199: manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion of a tree's root…
PriorityP345critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.40%
82.3th percentile
manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion of a tree's root, which might allow attackers to access a dangling pointer in an application whose developer was unaware of a documentation update from 1999.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.2-1 (bookworm) | glibc 2.2-1 (bookworm) |
| gnu | glibc | < 2.2 | 2.2 |
| gnu | glibc | >= 0 < 2.2-1 | 2.2-1 |
| gnu | glibc | >= 0 < 2.2-1 | 2.2-1 |
| gnu | glibc | >= 0 < 2.2-1 | 2.2-1 |
| gnu | glibc | >= 0 < 2.2-1 | 2.2-1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
glibc: manual/search.texi lacks a statement about the unspecified tdelete return value upon deletion of a tree's root
vendor_redhat·1999-11-09·CVSS 9.8
CVE-1999-0199 [CRITICAL] CWE-1053 glibc: manual/search.texi lacks a statement about the unspecified tdelete return value upon deletion of a tree's root
glibc: manual/search.texi lacks a statement about the unspecified tdelete return value upon deletion of a tree's root
manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion of a tree's root, which might allow attackers to access a dangling pointer in an application whose developer was unaware of a documentation update from 1999.
Statement: Red Hat Product Security does not feel that this issue has any security impact because the CVE description suggests that a missing statement in the manpage could lead to a generalized developer awareness problem, that in turn could potentially lead to a flaw. Thus, there is no actual exploitable vulnerability reported in this CVE, but rather, the possibility that one cou
Debian
CVE-1999-0199: glibc - manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement...
vendor_debian·1999·CVSS 9.8
CVE-1999-0199 [CRITICAL] CVE-1999-0199: glibc - manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement...
manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion of a tree's root, which might allow attackers to access a dangling pointer in an application whose developer was unaware of a documentation update from 1999.
Scope: local
bookworm: resolved (fixed in 2.2-1)
bullseye: resolved (fixed in 2.2-1)
forky: resolved (fixed in 2.2-1)
sid: resolved (fixed in 2.2-1)
trixie: resolved (fixed in 2.2-1)
GHSA
GHSA-7hm4-28mg-fmp9: manual/search
ghsa_unreviewed·2022-04-21
CVE-1999-0199 [CRITICAL] CWE-252 GHSA-7hm4-28mg-fmp9: manual/search
manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion of a tree's root, which might allow attackers to access a dangling pointer in an application whose developer was unaware of a documentation update from 1999.
OSV
CVE-1999-0199: manual/search
osv·2020-10-06·CVSS 9.8
CVE-1999-0199 [CRITICAL] CVE-1999-0199: manual/search
manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion of a tree's root, which might allow attackers to access a dangling pointer in an application whose developer was unaware of a documentation update from 1999.
No detection rules found.
No public exploits indexed.
https://ftp.gnu.org/gnu/glibc/glibc-2.2.tar.gzhttps://github.com/bminor/glibc/commit/2864e767053317538feafa815046fff89e5a16be#diff-94e8c502f255fdfc346df0e29fd4ef40https://www.cee.studio/tdelete.htmlhttps://ftp.gnu.org/gnu/glibc/glibc-2.2.tar.gzhttps://github.com/bminor/glibc/commit/2864e767053317538feafa815046fff89e5a16be#diff-94e8c502f255fdfc346df0e29fd4ef40https://www.cee.studio/tdelete.html
2020-10-06
Published