CVE-2010-2898
published 2010-07-28CVE-2010-2898: Google Chrome before 5.0.375.125 does not properly mitigate an unspecified flaw in the GNU C Library, which has unknown impact and attack vectors.
PriorityP427critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
1.03%
60.4th percentile
Google Chrome before 5.0.375.125 does not properly mitigate an unspecified flaw in the GNU C Library, which has unknown impact and attack vectors.
Affected
62 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.11.2-12 (bookworm) | glibc 2.11.2-12 (bookworm) |
| gnu | glibc | <= 2.12.1 | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w4p3-xg4g-ff4x: The GNU C Library (aka glibc or libc6) before 2
ghsa_unreviewed·2022-05-14·CVSS 5.0
CVE-2011-1071 [MEDIUM] GHSA-w4p3-xg4g-ff4x: The GNU C Library (aka glibc or libc6) before 2
The GNU C Library (aka glibc or libc6) before 2.12.2 and Embedded GLIBC (EGLIBC) allow context-dependent attackers to execute arbitrary code or cause a denial of service (memory consumption) via a long UTF8 string that is used in an fnmatch call, aka a "stack extension attack," a related issue to CVE-2010-2898, CVE-2010-1917, and CVE-2007-4782, as originally reported for use of this library by Google Chrome.
GHSA
GHSA-gc4p-2q2v-6m49: Google Chrome before 5
ghsa_unreviewed·2022-05-13
CVE-2010-2898 [HIGH] GHSA-gc4p-2q2v-6m49: Google Chrome before 5
Google Chrome before 5.0.375.125 does not properly mitigate an unspecified flaw in the GNU C Library, which has unknown impact and attack vectors.
OSV
CVE-2011-1071: The GNU C Library (aka glibc or libc6) before 2
osv·2011-04-08·CVSS 5.0
CVE-2011-1071 [MEDIUM] CVE-2011-1071: The GNU C Library (aka glibc or libc6) before 2
The GNU C Library (aka glibc or libc6) before 2.12.2 and Embedded GLIBC (EGLIBC) allow context-dependent attackers to execute arbitrary code or cause a denial of service (memory consumption) via a long UTF8 string that is used in an fnmatch call, aka a "stack extension attack," a related issue to CVE-2010-2898, CVE-2010-1917, and CVE-2007-4782, as originally reported for use of this library by Google Chrome.
Debian
CVE-2011-1071: glibc - The GNU C Library (aka glibc or libc6) before 2.12.2 and Embedded GLIBC (EGLIBC)...
vendor_debian·2011·CVSS 5.0
CVE-2011-1071 [MEDIUM] CVE-2011-1071: glibc - The GNU C Library (aka glibc or libc6) before 2.12.2 and Embedded GLIBC (EGLIBC)...
The GNU C Library (aka glibc or libc6) before 2.12.2 and Embedded GLIBC (EGLIBC) allow context-dependent attackers to execute arbitrary code or cause a denial of service (memory consumption) via a long UTF8 string that is used in an fnmatch call, aka a "stack extension attack," a related issue to CVE-2010-2898, CVE-2010-1917, and CVE-2007-4782, as originally reported for use of this library by Google Chrome.
Scope: local
bookworm: resolved (fixed in 2.11.2-12)
bullseye: resolved (fixed in 2.11.2-12)
forky: resolved (fixed in 2.11.2-12)
sid: resolved (fixed in 2.11.2-12)
trixie: resolved (fixed in 2.11.2-12)
Red Hat
glibc: fnmatch() alloca()-based memory corruption flaw
vendor_redhat·2010-08-05·CVSS 5.0
CVE-2011-1071 [MEDIUM] glibc: fnmatch() alloca()-based memory corruption flaw
glibc: fnmatch() alloca()-based memory corruption flaw
The GNU C Library (aka glibc or libc6) before 2.12.2 and Embedded GLIBC (EGLIBC) allow context-dependent attackers to execute arbitrary code or cause a denial of service (memory consumption) via a long UTF8 string that is used in an fnmatch call, aka a "stack extension attack," a related issue to CVE-2010-2898, CVE-2010-1917, and CVE-2007-4782, as originally reported for use of this library by Google Chrome.
Suricata
ET WEB_SPECIFIC_APPS 2z Project SQL Injection Attempt -- rating.php rating DELETE
suricata·2010-07-30·CVSS 7.5
CVE-2007-2898 [HIGH] ET WEB_SPECIFIC_APPS 2z Project SQL Injection Attempt -- rating.php rating DELETE
ET WEB_SPECIFIC_APPS 2z Project SQL Injection Attempt -- rating.php rating DELETE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS 2z Project SQL Injection Attempt -- rating.php rating DELETE"; flow:established,to_server; http.uri; content:"/includes/rating.php?"; nocase; content:"rating="; nocase; content:"DELETE"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-2898; reference:url,www.securityfocus.com/archive/1/archive/1/469351/100/0/threaded; classtype:web-application-attack; sid:2004062; rev:13; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_
Suricata
ET WEB_SPECIFIC_APPS Hedgehog CMS footer.php c_temp_path Remote File Inclusion
suricata·2010-07-30·CVSS 9.3
CVE-2008-2898 [CRITICAL] ET WEB_SPECIFIC_APPS Hedgehog CMS footer.php c_temp_path Remote File Inclusion
ET WEB_SPECIFIC_APPS Hedgehog CMS footer.php c_temp_path Remote File Inclusion
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Hedgehog CMS footer.php c_temp_path Remote File Inclusion"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/includes/footer.php?"; nocase; content:"c_temp_path"; nocase; pcre:"/c_temp_path=\s*(https?|ftps?|php)\:\//i"; reference:cve,CVE-2008-2898; reference:url,secunia.com/advisories/30778/; reference:url,milw0rm.com/exploits/8028; classtype:web-application-attack; sid:2009232; rev:8; metadata:created_at 2010_07_30, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_06, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_tec
Suricata
ET WEB_SPECIFIC_APPS Hedgehog CMS header.php c_temp_path Remote File Inclusion
suricata·2010-07-30·CVSS 9.3
CVE-2008-2898 [CRITICAL] ET WEB_SPECIFIC_APPS Hedgehog CMS header.php c_temp_path Remote File Inclusion
ET WEB_SPECIFIC_APPS Hedgehog CMS header.php c_temp_path Remote File Inclusion
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Hedgehog CMS header.php c_temp_path Remote File Inclusion"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/includes/header.php?"; nocase; content:"c_temp_path"; nocase; pcre:"/c_temp_path=\s*(https?|ftps?|php)\:\//i"; reference:cve,CVE-2008-2898; reference:url,secunia.com/advisories/30778/; reference:url,milw0rm.com/exploits/5904; classtype:web-application-attack; sid:2009233; rev:8; metadata:created_at 2010_07_30, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_06, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_tec
Suricata
ET WEB_SPECIFIC_APPS 2z Project SQL Injection Attempt -- rating.php rating INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2007-2898 [HIGH] ET WEB_SPECIFIC_APPS 2z Project SQL Injection Attempt -- rating.php rating INSERT
ET WEB_SPECIFIC_APPS 2z Project SQL Injection Attempt -- rating.php rating INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS 2z Project SQL Injection Attempt -- rating.php rating INSERT"; flow:established,to_server; http.uri; content:"/includes/rating.php?"; nocase; content:"rating="; nocase; content:"INSERT"; nocase; content:"INTO"; nocase; distance:0; reference:cve,CVE-2007-2898; reference:url,www.securityfocus.com/archive/1/archive/1/469351/100/0/threaded; classtype:web-application-attack; sid:2004061; rev:13; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_
Suricata
ET WEB_SPECIFIC_APPS Hedgehog CMS header.php c_temp_path Local File Inclusion
suricata·2010-07-30·CVSS 9.3
CVE-2008-2898 [CRITICAL] ET WEB_SPECIFIC_APPS Hedgehog CMS header.php c_temp_path Local File Inclusion
ET WEB_SPECIFIC_APPS Hedgehog CMS header.php c_temp_path Local File Inclusion
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Hedgehog CMS header.php c_temp_path Local File Inclusion"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/includes/header.php?"; fast_pattern; nocase; content:"c_temp_path="; nocase; http.uri.raw; url_decode; content:"|2e 2e 2f|"; reference:cve,CVE-2008-2898; reference:url,secunia.com/advisories/30778/; reference:url,milw0rm.com/exploits/5904; classtype:web-application-attack; sid:2009231; rev:9; metadata:affected_product Web_Server_Applications, attack_target Server, created_at 2010_07_30, deployment Perimeter, deployment Internal, deployment Datacenter, confidence High, signature_severity Major, tag
Suricata
ET WEB_SPECIFIC_APPS 2z Project SQL Injection Attempt -- rating.php rating SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-2898 [HIGH] ET WEB_SPECIFIC_APPS 2z Project SQL Injection Attempt -- rating.php rating SELECT
ET WEB_SPECIFIC_APPS 2z Project SQL Injection Attempt -- rating.php rating SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS 2z Project SQL Injection Attempt -- rating.php rating SELECT"; flow:established,to_server; http.uri; content:"/includes/rating.php?"; nocase; content:"rating="; nocase; content:"SELECT"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-2898; reference:url,www.securityfocus.com/archive/1/archive/1/469351/100/0/threaded; classtype:web-application-attack; sid:2004059; rev:13; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_
Suricata
ET WEB_SPECIFIC_APPS 2z Project SQL Injection Attempt -- rating.php rating UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-2898 [HIGH] ET WEB_SPECIFIC_APPS 2z Project SQL Injection Attempt -- rating.php rating UNION SELECT
ET WEB_SPECIFIC_APPS 2z Project SQL Injection Attempt -- rating.php rating UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS 2z Project SQL Injection Attempt -- rating.php rating UNION SELECT"; flow:established,to_server; http.uri; content:"/includes/rating.php?"; nocase; content:"rating="; nocase; content:"UNION"; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-2898; reference:url,www.securityfocus.com/archive/1/archive/1/469351/100/0/threaded; classtype:web-application-attack; sid:2004060; rev:13; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id T
Suricata
ET WEB_SPECIFIC_APPS 2z Project SQL Injection Attempt -- rating.php rating ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2007-2898 [HIGH] ET WEB_SPECIFIC_APPS 2z Project SQL Injection Attempt -- rating.php rating ASCII
ET WEB_SPECIFIC_APPS 2z Project SQL Injection Attempt -- rating.php rating ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS 2z Project SQL Injection Attempt -- rating.php rating ASCII"; flow:established,to_server; http.uri; content:"/includes/rating.php?"; nocase; content:"rating="; nocase; content:"ASCII("; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-2898; reference:url,www.securityfocus.com/archive/1/archive/1/469351/100/0/threaded; classtype:web-application-attack; sid:2004063; rev:13; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_
Suricata
ET WEB_SPECIFIC_APPS 2z Project SQL Injection Attempt -- rating.php rating UPDATE
suricata·2010-07-30·CVSS 7.5
CVE-2007-2898 [HIGH] ET WEB_SPECIFIC_APPS 2z Project SQL Injection Attempt -- rating.php rating UPDATE
ET WEB_SPECIFIC_APPS 2z Project SQL Injection Attempt -- rating.php rating UPDATE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS 2z Project SQL Injection Attempt -- rating.php rating UPDATE"; flow:established,to_server; http.uri; content:"/includes/rating.php?"; nocase; content:"rating="; nocase; content:"UPDATE"; nocase; content:"SET"; nocase; distance:0; reference:cve,CVE-2007-2898; reference:url,www.securityfocus.com/archive/1/archive/1/469351/100/0/threaded; classtype:web-application-attack; sid:2004064; rev:13; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_t
No public exploits indexed.
No writeups or analysis indexed.
http://code.google.com/p/chromium/issues/detail?id=48733http://googlechromereleases.blogspot.com/2010/07/stable-channel-update_26.htmlhttp://secunia.com/advisories/40743https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12104http://code.google.com/p/chromium/issues/detail?id=48733http://googlechromereleases.blogspot.com/2010/07/stable-channel-update_26.htmlhttp://secunia.com/advisories/40743https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12104
2010-07-28
Published