CVE-2003-0689Improper Restriction of Operations within the Bounds of a Memory Buffer in Redhat Enterprise Linux

7 documents7 sources
Severity
7.5HIGHNVD
EPSS
0.9%
top 24.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 20
Latest updateApr 29

Description

The getgrouplist function in GNU libc (glibc) 2.2.4 and earlier allows attackers to cause a denial of service (segmentation fault) and execute arbitrary code when a user is a member of a large number of groups, which can cause a buffer overflow.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

Debiangnu/glibc< 2.2.5+3

Also affects: Enterprise Linux 2.1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-q58h-j692-6gh6: The getgrouplist function in GNU libc (glibc) 22022-04-29
OSV
CVE-2003-0689: The getgrouplist function in GNU libc (glibc) 22003-10-20
CVEList
CVE-2003-0689: The getgrouplist function in GNU libc (glibc) 22003-09-03

📋Vendor Advisories

2
Red Hat
security flaw2003-04-01
Debian
CVE-2003-0689: glibc - The getgrouplist function in GNU libc (glibc) 2.2.4 and earlier allows attackers...2003

💬Community

1
Bugzilla
CVE-2003-0689 security flaw2018-08-16
CVE-2003-0689 — Redhat Enterprise Linux vulnerability | cvebase