cbcvebase.
CVE-2009-5029
published 2013-05-02

CVE-2009-5029: Integer overflow in the __tzfile_read function in glibc before 2.15 allows context-dependent attackers to cause a denial of service (crash) and possibly…

PriorityP339medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EXPLOIT
EPSS
8.07%
94.2th percentile
Integer overflow in the __tzfile_read function in glibc before 2.15 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted timezone (TZ) file, as demonstrated using vsftpd.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianglibc< glibc 2.13-24 (bookworm)glibc 2.13-24 (bookworm)
gnuglibc<= 2.14
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc>= 0 < 2.13-242.13-24
gnuglibc>= 0 < 2.13-242.13-24
gnuglibc>= 0 < 2.13-242.13-24
gnuglibc>= 0 < 2.13-242.13-24
vmwarevcenter_server
vmwarevmware_esxi
vmwarevsphere

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu6.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.