CVE-2010-4756Glibc vulnerability

6 documents6 sources
Severity
4.0MEDIUMNVD
OSV7.8
EPSS
0.4%
top 39.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 2
Latest updateMay 13

Description

The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 8.0 | Impact: 2.9

Affected Packages1 packages

debiandebian/glibc

🔴Vulnerability Details

2
GHSA
GHSA-x2r9-jfjp-jvp9: The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consu2022-05-13
OSV
CVE-2010-4756: The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consu2011-03-02

📋Vendor Advisories

2
Red Hat
glibc: glob implementation can cause excessive CPU and memory consumption due to crafted glob expressions2010-10-07
Debian
CVE-2010-4756: glibc - The glob implementation in the GNU C Library (aka glibc or libc6) allows remote ...2010

💬Community

1
Bugzilla
CVE-2010-4756 glibc: glob implementation can cause excessive CPU and memory consumption due to crafted glob expressions2011-03-02