cbcvebase.
CVE-2009-5029
published 2013-05-02

CVE-2009-5029: Integer overflow in the __tzfile_read function in glibc before 2.15 allows context-dependent attackers to cause a denial of service (crash) and possibly…

medium6.8CVSS 3.1
AVNACMAuNCPIPAP
EXPLOIT
Integer overflow in the __tzfile_read function in glibc before 2.15 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted timezone (TZ) file, as demonstrated using vsftpd.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianglibc< glibc 2.13-24 (bookworm)glibc 2.13-24 (bookworm)
gnuglibc<= 2.14
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc>= 0 < 2.13-242.13-24
gnuglibc>= 0 < 2.13-242.13-24
gnuglibc>= 0 < 2.13-242.13-24
gnuglibc>= 0 < 2.13-242.13-24
vmwarevcenter_server
vmwarevmware_esxi
vmwarevsphere

CVSS provenance

nvd6.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM