CVE-2010-0296Improper Input Validation in Glibc

Severity
7.2HIGHNVD
EPSS
0.1%
top 69.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 1
Latest updateMay 2

Description

The encode_name macro in misc/mntent_r.c in the GNU C Library (aka glibc or libc6) 2.11.1 and earlier, as used by ncpmount and mount.cifs, does not properly handle newline characters in mountpoint names, which allows local users to cause a denial of service (mtab corruption), or possibly modify mount options and gain privileges, via a crafted mount request.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages2 packages

Debiangnu/glibc< 2.11-1+3
NVDgnu/glibc2.11.1+38

🔴Vulnerability Details

3
GHSA
GHSA-8hvc-pfj5-96x6: The encode_name macro in misc/mntent_r2022-05-02
CVEList
CVE-2010-0296: The encode_name macro in misc/mntent_r2010-06-01
OSV
CVE-2010-0296: The encode_name macro in misc/mntent_r2010-06-01

📋Vendor Advisories

4
Red Hat
glibc: Suid mount helpers fail to anticipate RLIMIT_FSIZE2011-03-03
Ubuntu
GNU C Library vulnerabilities2010-05-25
Red Hat
glibc: Improper encoding of names with certain special character in utilities for writing to mtab table2010-05-25
Debian
CVE-2010-0296: glibc - The encode_name macro in misc/mntent_r.c in the GNU C Library (aka glibc or libc...2010

💬Community

2
Bugzilla
CVE-2010-0296 glibc: Improper encoding of names with certain special character in utilities for writing to mtab table [Fedora 11]2010-06-02
Bugzilla
CVE-2010-0296 glibc: Improper encoding of names with certain special character in utilities for writing to mtab table2010-01-28
CVE-2010-0296 — Improper Input Validation in GNU Glibc | cvebase