CVE-2010-4051
published 2011-01-13CVE-2010-4051: The regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a…
PriorityP340medium5CVSS 2.0
AVNACLAuNCNINAP
EXPLOIT
EPSS
40.00%
98.5th percentile
The regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (application crash) via a regular expression containing adjacent bounded repetitions that bypass the intended RE_DUP_MAX limitation, as demonstrated by a {10,}{10,}{10,}{10,}{10,} sequence in the proftpd.gnu.c exploit for ProFTPD, related to a "RE_DUP_MAX overflow."
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.19-4 (bookworm) | glibc 2.19-4 (bookworm) |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
glibc: De-recursivise regular expression engine
vendor_redhat·2010-12-07·CVSS 5.0
CVE-2010-4051 [MEDIUM] glibc: De-recursivise regular expression engine
glibc: De-recursivise regular expression engine
The regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (application crash) via a regular expression containing adjacent bounded repetitions that bypass the intended RE_DUP_MAX limitation, as demonstrated by a {10,}{10,}{10,}{10,}{10,} sequence in the proftpd.gnu.c exploit for ProFTPD, related to a "RE_DUP_MAX overflow."
Statement: Red Hat does not consider crash of client application, using regcomp()
or regexec() routines on untrusted input without preliminary checking
the input for the sanity, to be a security issue (the described deficiency
implies and is a known limitation of the glibc regular expression engine
impleme
Debian
CVE-2010-4051: glibc - The regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.1...
vendor_debian·2010·CVSS 5.0
CVE-2010-4051 [MEDIUM] CVE-2010-4051: glibc - The regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.1...
The regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (application crash) via a regular expression containing adjacent bounded repetitions that bypass the intended RE_DUP_MAX limitation, as demonstrated by a {10,}{10,}{10,}{10,}{10,} sequence in the proftpd.gnu.c exploit for ProFTPD, related to a "RE_DUP_MAX overflow."
Scope: local
bookworm: resolved (fixed in 2.19-4)
bullseye: resolved (fixed in 2.19-4)
forky: resolved (fixed in 2.19-4)
sid: resolved (fixed in 2.19-4)
trixie: resolved (fixed in 2.19-4)
GHSA
GHSA-6429-fc4p-f7q7: The regcomp implementation in the GNU C Library (aka glibc or libc6) through 2
ghsa_unreviewed·2022-05-13
CVE-2010-4051 [MEDIUM] GHSA-6429-fc4p-f7q7: The regcomp implementation in the GNU C Library (aka glibc or libc6) through 2
The regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (application crash) via a regular expression containing adjacent bounded repetitions that bypass the intended RE_DUP_MAX limitation, as demonstrated by a {10,}{10,}{10,}{10,}{10,} sequence in the proftpd.gnu.c exploit for ProFTPD, related to a "RE_DUP_MAX overflow."
OSV
CVE-2010-4051: The regcomp implementation in the GNU C Library (aka glibc or libc6) through 2
osv·2011-01-13·CVSS 5.0
CVE-2010-4051 [MEDIUM] CVE-2010-4051: The regcomp implementation in the GNU C Library (aka glibc or libc6) through 2
The regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (application crash) via a regular expression containing adjacent bounded repetitions that bypass the intended RE_DUP_MAX limitation, as demonstrated by a {10,}{10,}{10,}{10,}{10,} sequence in the proftpd.gnu.c exploit for ProFTPD, related to a "RE_DUP_MAX overflow."
No detection rules found.
Exploit-DB
FreeBSD 9.1 - 'ftpd' Remote Denial of Service
exploitdb·2013-02-05·CVSS 4.0
CVE-2011-0418 [MEDIUM] FreeBSD 9.1 - 'ftpd' Remote Denial of Service
FreeBSD 9.1 - 'ftpd' Remote Denial of Service
---
FreeBSD 9.1 ftpd Remote Denial of Service
Maksymilian Arciemowicz
http://cxsecurity.org/
http://cxsec.org/
Public Date: 01.02.2013
URL: http://cxsecurity.com/issue/WLB-2013020003
--- 1. Description ---
I have decided check BSD ftpd servers once again for wildcards. Old
bug in libc (CVE-2011-0418) allow to Denial of Service ftpd in last
FreeBSD version.
Attacker, what may connect anonymously to FTP server, may cause CPU
resource exhaustion. Login as a 'USER anonymous' 'PASS anonymous',
sending 'STAT' command with special wildchar, enought to create ftpd
process with 100% CPU usage.
Proof of Concept (POC):
See the difference between NetBSD/libc and FreeBSD/libc.
--- PoC ---
#include
#include
int main(){
glob_t globbuf;
char stringa[]="{
Exploit-DB
GNU libc/regcomp(3) - Multiple Vulnerabilities
exploitdb·2011-01-07·CVSS 5.0
CVE-2010-4051 [MEDIUM] GNU libc/regcomp(3) - Multiple Vulnerabilities
GNU libc/regcomp(3) - Multiple Vulnerabilities
---
// source: http://securityreason.com/securityalert/8003
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
[ GNU libc/regcomp(3) Multiple Vulnerabilities ]
Author: Maksymilian Arciemowicz
http://securityreason.com/
http://cxib.net/
Date:
- - Dis.: 01.10.2010
- - Pub.: 07.01.2011
CERT: VU#912279
CVE:
CVE-2010-4051
CVE-2010-4052
Affected (tested):
- - Ubuntu 10.10
- - Slackware 13
- - Gentoo 18.10.2010
- - FreeBSD 8.1 (grep(1))
- - NetBSD 5.0.2 (grep(1))
Original URL:
http://securityreason.com/achievement_securityalert/93
Exploit for proftpd:
http://cxib.net/stuff/proftpd.gnu.c
- --- 0.Description ---
The GNU C library is used as the C library in the GNU system and most
systems with the Linux kernel.
# define RE_DUP_MAX (0x7fff)
regc
Exploit-DB
GNU glibc - 'regcomp()' Stack Exhaustion Denial of Service
exploitdb·2010-12-07·CVSS 5.0
CVE-2010-4052 [MEDIUM] GNU glibc - 'regcomp()' Stack Exhaustion Denial of Service
GNU glibc - 'regcomp()' Stack Exhaustion Denial of Service
---
// source: https://www.securityfocus.com/bid/45233/info
GNU glibc is prone to a denial-of-service vulnerability due to stack exhaustion.
Successful exploits will allow attackers to make the affected computer unresponsive, denying service to legitimate users.
This issue affects unknown versions of the glibc library. This BID will be updated when more details become available.
#include
#include
#include
#include
#include
#include
#include
/*
proftpd multiple exploit for VU#912279 (only with GNU libc/regcomp(3))
by Maksymilian Arciemowicz
References:
http://www.kb.cert.org/vuls/id/912279
http://cxib.net/
http://securityreason.com/
Tested:
Ubuntu + proftpd
This exploit need writing privileges to create .ftpaccess file wi
arXiv
Fuzzing BusyBox: Leveraging LLM and Crash Reuse for Embedded Bug Unearthing
arxiv_fulltext·2024-03-06
Fuzzing BusyBox: Leveraging LLM and Crash Reuse for Embedded Bug Unearthing
Fuzzing BusyBox: Leveraging LLM and Crash Reuse for Embedded Bug Unearthing
Asmita^1, Yaroslav Oliinyk^2, Michael Scott^2, Ryan Tsang^1,
Chongzhou Fang^1, Houman Homayoun^1
^1University of California, Davis
^2NetRise
## Abstract
BusyBox, an open-source software bundling over 300 essential Linux commands into a single executable, is ubiquitous in Linux-based embedded devices. Vulnerabilities in BusyBox can have far-reaching consequences, affecting a wide array of devices. This research, driven by the extensive use of BusyBox, delved into its analysis. The study revealed the prevalence of older BusyBox versions in real-world embedded products, prompting us to conduct fuzz testing on BusyBox. Fuzzing, a pivotal software testing method, aims to induce crashes that are subsequently scrutini
Bugzilla
CVE-2010-4051 CVE-2010-4052 glibc: De-recursivise regular expression engine
bugzilla·2010-10-22·CVSS 5.0
CVE-2010-4051 [MEDIUM] CVE-2010-4051 CVE-2010-4052 glibc: De-recursivise regular expression engine
CVE-2010-4051 CVE-2010-4052 glibc: De-recursivise regular expression engine
Maksymilian Arciemowicz reported a deficiency in the way
glibc regular expression engine processed certain patterns.
A local attacker could use this flaw to cause a denial of
service (crash due stack overflow).
Note: The above described behavior is a limitation of glibc
regular expression engine. Regular expression matching
function is called recursively for certain types of patterns
(where subexpression using quantifier is nested inside of
another quantified expression), where long input can result
in deep recursion and exhaustion of all stack memory (i.e.
impact is limited to crash). Amount of stack memory available
to glibc regular expression engine influences the size of input
that must be provided to trigger
http://cxib.net/stuff/proftpd.gnu.chttp://seclists.org/fulldisclosure/2011/Jan/78http://secunia.com/advisories/42547http://securityreason.com/achievement_securityalert/93http://securityreason.com/securityalert/8003http://securitytracker.com/id?1024832http://www.exploit-db.com/exploits/15935http://www.kb.cert.org/vuls/id/912279http://www.securityfocus.com/archive/1/515589/100/0/threadedhttp://www.securityfocus.com/bid/45233https://bugzilla.redhat.com/show_bug.cgi?id=645859https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c%40%3Cissues.guacamole.apache.org%3Ehttp://cxib.net/stuff/proftpd.gnu.chttp://seclists.org/fulldisclosure/2011/Jan/78http://secunia.com/advisories/42547http://securityreason.com/achievement_securityalert/93http://securityreason.com/securityalert/8003http://securitytracker.com/id?1024832http://www.exploit-db.com/exploits/15935http://www.kb.cert.org/vuls/id/912279http://www.securityfocus.com/archive/1/515589/100/0/threadedhttp://www.securityfocus.com/bid/45233https://bugzilla.redhat.com/show_bug.cgi?id=645859https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c%40%3Cissues.guacamole.apache.org%3E
2011-01-13
Published