CVE-2010-0830Glibc vulnerability

CWE-1898 documents8 sources
Severity
5.1MEDIUMNVD
EPSS
6.3%
top 9.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 1
Latest updateMay 2

Description

Integer signedness error in the elf_get_dynamic_info function in elf/dynamic-link.h in ld.so in the GNU C Library (aka glibc or libc6) 2.0.1 through 2.11.1, when the --verify option is used, allows user-assisted remote attackers to execute arbitrary code via a crafted ELF program with a negative value for a certain d_tag structure member in the ELF header.

CVSS vector

AV:N/AC:H/C:P/I:P/A:PExploitability: 4.9 | Impact: 6.4

Affected Packages2 packages

Debiangnu/glibc< 2.11-1+3
NVDgnu/glibc38 versions+37

Patches

🔴Vulnerability Details

3
GHSA
GHSA-5gq9-qhr6-c66r: Integer signedness error in the elf_get_dynamic_info function in elf/dynamic-link2022-05-02
OSV
CVE-2010-0830: Integer signedness error in the elf_get_dynamic_info function in elf/dynamic-link2010-06-01
CVEList
CVE-2010-0830: Integer signedness error in the elf_get_dynamic_info function in elf/dynamic-link2010-06-01

📋Vendor Advisories

3
Ubuntu
GNU C Library vulnerabilities2010-05-25
Red Hat
glibc: ld.so d_tag signedness error in elf_get_dynamic_info2010-05-25
Debian
CVE-2010-0830: glibc - Integer signedness error in the elf_get_dynamic_info function in elf/dynamic-lin...2010

💬Community

1
Bugzilla
CVE-2010-0830 glibc: ld.so d_tag signedness error in elf_get_dynamic_info2010-06-02
CVE-2010-0830 — GNU Glibc vulnerability | cvebase