CVE-2011-1071
published 2011-04-08CVE-2011-1071: The GNU C Library (aka glibc or libc6) before 2.12.2 and Embedded GLIBC (EGLIBC) allow context-dependent attackers to execute arbitrary code or cause a denial…
PriorityP340medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EXPLOIT
EPSS
14.32%
96.2th percentile
The GNU C Library (aka glibc or libc6) before 2.12.2 and Embedded GLIBC (EGLIBC) allow context-dependent attackers to execute arbitrary code or cause a denial of service (memory consumption) via a long UTF8 string that is used in an fnmatch call, aka a "stack extension attack," a related issue to CVE-2010-2898, CVE-2010-1917, and CVE-2007-4782, as originally reported for use of this library by Google Chrome.
Affected
72 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.13-8 (bookworm) | glibc 2.13-8 (bookworm) |
| debian | glibc | < glibc 2.11.2-12 (bookworm) | glibc 2.11.2-12 (bookworm) |
| gnu | glibc | <= 2.13 | — |
| gnu | glibc | <= 2.12.1 | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
CVSS provenance
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv5.1MEDIUM
vendor_ubuntu6.8MEDIUM
vendor_debian5.1MEDIUM
vendor_redhat5.1MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q5rg-jqvh-mj2q: Integer overflow in posix/fnmatch
ghsa_unreviewed·2022-05-14·CVSS 5.1
CVE-2011-1659 [MEDIUM] GHSA-q5rg-jqvh-mj2q: Integer overflow in posix/fnmatch
Integer overflow in posix/fnmatch.c in the GNU C Library (aka glibc or libc6) 2.13 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long UTF8 string that is used in an fnmatch call with a crafted pattern argument, a different vulnerability than CVE-2011-1071.
GHSA
GHSA-w4p3-xg4g-ff4x: The GNU C Library (aka glibc or libc6) before 2
ghsa_unreviewed·2022-05-14·CVSS 5.0
CVE-2011-1071 [MEDIUM] GHSA-w4p3-xg4g-ff4x: The GNU C Library (aka glibc or libc6) before 2
The GNU C Library (aka glibc or libc6) before 2.12.2 and Embedded GLIBC (EGLIBC) allow context-dependent attackers to execute arbitrary code or cause a denial of service (memory consumption) via a long UTF8 string that is used in an fnmatch call, aka a "stack extension attack," a related issue to CVE-2010-2898, CVE-2010-1917, and CVE-2007-4782, as originally reported for use of this library by Google Chrome.
OSV
CVE-2011-1071: The GNU C Library (aka glibc or libc6) before 2
osv·2011-04-08·CVSS 5.0
CVE-2011-1071 [MEDIUM] CVE-2011-1071: The GNU C Library (aka glibc or libc6) before 2
The GNU C Library (aka glibc or libc6) before 2.12.2 and Embedded GLIBC (EGLIBC) allow context-dependent attackers to execute arbitrary code or cause a denial of service (memory consumption) via a long UTF8 string that is used in an fnmatch call, aka a "stack extension attack," a related issue to CVE-2010-2898, CVE-2010-1917, and CVE-2007-4782, as originally reported for use of this library by Google Chrome.
OSV
CVE-2011-1659: Integer overflow in posix/fnmatch
osv·2011-04-08·CVSS 5.1
CVE-2011-1659 [MEDIUM] CVE-2011-1659: Integer overflow in posix/fnmatch
Integer overflow in posix/fnmatch.c in the GNU C Library (aka glibc or libc6) 2.13 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long UTF8 string that is used in an fnmatch call with a crafted pattern argument, a different vulnerability than CVE-2011-1071.
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2012-03-09·CVSS 6.8
CVE-2009-5029 [MEDIUM] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Multiple vulnerabilities were discovered and fixed in the GNU C Library.
It was discovered that the GNU C Library did not properly handle
integer overflows in the timezone handling code. An attacker could use
this to possibly execute arbitrary code by convincing an application
to load a maliciously constructed tzfile. (CVE-2009-5029)
It was discovered that the GNU C Library did not properly handle
passwd.adjunct.byname map entries in the Network Information Service
(NIS) code in the name service caching daemon (nscd). An attacker
could use this to obtain the encrypted passwords of NIS accounts.
This issue only affected Ubuntu 8.04 LTS. (CVE-2010-0015)
Chris Evans reported that the GNU C Library did not properly
calculate the amount of memor
VMware
VMware ESX third party updates for Service Console packages glibc and dhcp
vendor_vmware·2011-10-12·CVSS 4.7
CVE-2010-0296 [MEDIUM] VMware ESX third party updates for Service Console packages glibc and dhcp
VMSA-2011-0012: VMware ESX third party updates for Service Console packages glibc and dhcp
a. ESX third party update for Service Console kernel This update takes the console OS kernel package to kernel-2.6.18-238.9.1 which resolves multiple security issues. The Common Vulnerabilities and Exposures project ( cve.mitre.org) has assigned the names CVE-2010-1083, CVE-2010-2492, CVE-2010-2798, CVE-2010-2938, CVE-2010-2942, CVE-2010-2943, CVE-2010-3015, CVE-2010-3066, CVE-2010-3067, CVE-2010-3078, CVE-2010-3086, CVE-2010-3296, CVE-2010-3432, CVE-2010-3442, CVE-2010-3477, CVE-2010-3699, CVE-2010-3858, CVE-2010-3859, CVE-2010-3865, CVE-2010-3876, CVE-2010-3877, CVE-2010-3880, CVE-2010-3904, CVE-2010-4072, CVE-2010-4073, CVE-2010-4075, CVE-2010-4080, CVE-2010-4081, CVE-2010-4083, CVE-2010-4157, CV
Debian
CVE-2011-1659: glibc - Integer overflow in posix/fnmatch.c in the GNU C Library (aka glibc or libc6) 2....
vendor_debian·2011·CVSS 5.1
CVE-2011-1659 [MEDIUM] CVE-2011-1659: glibc - Integer overflow in posix/fnmatch.c in the GNU C Library (aka glibc or libc6) 2....
Integer overflow in posix/fnmatch.c in the GNU C Library (aka glibc or libc6) 2.13 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long UTF8 string that is used in an fnmatch call with a crafted pattern argument, a different vulnerability than CVE-2011-1071.
Scope: local
bookworm: resolved (fixed in 2.13-8)
bullseye: resolved (fixed in 2.13-8)
forky: resolved (fixed in 2.13-8)
sid: resolved (fixed in 2.13-8)
trixie: resolved (fixed in 2.13-8)
Debian
CVE-2011-1071: glibc - The GNU C Library (aka glibc or libc6) before 2.12.2 and Embedded GLIBC (EGLIBC)...
vendor_debian·2011·CVSS 5.0
CVE-2011-1071 [MEDIUM] CVE-2011-1071: glibc - The GNU C Library (aka glibc or libc6) before 2.12.2 and Embedded GLIBC (EGLIBC)...
The GNU C Library (aka glibc or libc6) before 2.12.2 and Embedded GLIBC (EGLIBC) allow context-dependent attackers to execute arbitrary code or cause a denial of service (memory consumption) via a long UTF8 string that is used in an fnmatch call, aka a "stack extension attack," a related issue to CVE-2010-2898, CVE-2010-1917, and CVE-2007-4782, as originally reported for use of this library by Google Chrome.
Scope: local
bookworm: resolved (fixed in 2.11.2-12)
bullseye: resolved (fixed in 2.11.2-12)
forky: resolved (fixed in 2.11.2-12)
sid: resolved (fixed in 2.11.2-12)
trixie: resolved (fixed in 2.11.2-12)
Red Hat
glibc: fnmatch() alloca()-based memory corruption flaw
vendor_redhat·2010-08-05·CVSS 5.0
CVE-2011-1071 [MEDIUM] glibc: fnmatch() alloca()-based memory corruption flaw
glibc: fnmatch() alloca()-based memory corruption flaw
The GNU C Library (aka glibc or libc6) before 2.12.2 and Embedded GLIBC (EGLIBC) allow context-dependent attackers to execute arbitrary code or cause a denial of service (memory consumption) via a long UTF8 string that is used in an fnmatch call, aka a "stack extension attack," a related issue to CVE-2010-2898, CVE-2010-1917, and CVE-2007-4782, as originally reported for use of this library by Google Chrome.
Red Hat
glibc: fnmatch() alloca()-based memory corruption flaw
vendor_redhat·2010-08-05·CVSS 5.1
CVE-2011-1659 [MEDIUM] glibc: fnmatch() alloca()-based memory corruption flaw
glibc: fnmatch() alloca()-based memory corruption flaw
Integer overflow in posix/fnmatch.c in the GNU C Library (aka glibc or libc6) 2.13 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long UTF8 string that is used in an fnmatch call with a crafted pattern argument, a different vulnerability than CVE-2011-1071.
No detection rules found.
Bugzilla
CVE-2011-1071 CVE-2011-1659 glibc: fnmatch() alloca()-based memory corruption flaw
bugzilla·2011-02-28·CVSS 5.1
CVE-2011-1071 [MEDIUM] CVE-2011-1071 CVE-2011-1659 glibc: fnmatch() alloca()-based memory corruption flaw
CVE-2011-1071 CVE-2011-1659 glibc: fnmatch() alloca()-based memory corruption flaw
It was reported [1] that glibc had a bug where it would use alloca() for the length of a user-supplied UTF8 string, times four (with additional integer overflow in the times four). This could lead to an application crash, because alloca() extends the stack.
This was reported upstream [2] and subsequently fixed upstream [3].
References:
[1] http://scarybeastsecurity.blogspot.com/2011/02/i-got-accidental-code-execution-via.html
[2] http://sourceware.org/bugzilla/show_bug.cgi?id=11883
[3] http://sourceware.org/git/?p=glibc.git;a=commitdiff;h=f15ce4d8dc139523fe0c273580b604b2453acba6
Discussion:
This post implies that proftpd is affected (as it pulled its fnmatch implementation from glibc):
http://seclists
arXiv
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
arxiv_fulltext·2022-12-29
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
## Abstract
Currently, the development of IoT firmware heavily depends on third-party components (TPCs) to improve development efficiency. Nevertheless, TPCs are not secure, and the vulnerabilities in TPCs will influence the security of IoT firmware. Existing works pay less attention to the vulnerabilities caused by TPCs, and we still lack a comprehensive understanding of the security impact of TPC vulnerability against firmware. To fill in the knowledge gap, we design and implement , which leverages syntactical features and control-flow graph features to detect the TPCs in firmware, and then recognizes the corresponding vulnerabilities. Based on , we present the first l
http://bugs.debian.org/615120http://code.google.com/p/chromium/issues/detail?id=48733http://openwall.com/lists/oss-security/2011/02/26/3http://openwall.com/lists/oss-security/2011/02/28/11http://openwall.com/lists/oss-security/2011/02/28/15http://scarybeastsecurity.blogspot.com/2011/02/i-got-accidental-code-execution-via.htmlhttp://seclists.org/fulldisclosure/2011/Feb/635http://seclists.org/fulldisclosure/2011/Feb/644http://secunia.com/advisories/43492http://secunia.com/advisories/43830http://secunia.com/advisories/43989http://secunia.com/advisories/46397http://securityreason.com/securityalert/8175http://securitytracker.com/id?1025290http://sourceware.org/bugzilla/show_bug.cgi?id=11883http://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=f15ce4d8dc139523fe0c273580b604b2453acba6http://www.mandriva.com/security/advisories?name=MDVSA-2011:178http://www.redhat.com/support/errata/RHSA-2011-0412.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0413.htmlhttp://www.securityfocus.com/archive/1/520102/100/0/threadedhttp://www.securityfocus.com/bid/46563http://www.vmware.com/security/advisories/VMSA-2011-0012.htmlhttp://www.vupen.com/english/advisories/2011/0863https://bugzilla.redhat.com/show_bug.cgi?id=681054https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12853http://bugs.debian.org/615120http://code.google.com/p/chromium/issues/detail?id=48733http://openwall.com/lists/oss-security/2011/02/26/3http://openwall.com/lists/oss-security/2011/02/28/11http://openwall.com/lists/oss-security/2011/02/28/15http://scarybeastsecurity.blogspot.com/2011/02/i-got-accidental-code-execution-via.htmlhttp://seclists.org/fulldisclosure/2011/Feb/635http://seclists.org/fulldisclosure/2011/Feb/644http://secunia.com/advisories/43492http://secunia.com/advisories/43830http://secunia.com/advisories/43989http://secunia.com/advisories/46397http://securityreason.com/securityalert/8175http://securitytracker.com/id?1025290http://sourceware.org/bugzilla/show_bug.cgi?id=11883http://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=f15ce4d8dc139523fe0c273580b604b2453acba6http://www.mandriva.com/security/advisories?name=MDVSA-2011:178http://www.redhat.com/support/errata/RHSA-2011-0412.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0413.htmlhttp://www.securityfocus.com/archive/1/520102/100/0/threadedhttp://www.securityfocus.com/bid/46563http://www.vmware.com/security/advisories/VMSA-2011-0012.htmlhttp://www.vupen.com/english/advisories/2011/0863https://bugzilla.redhat.com/show_bug.cgi?id=681054https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12853
2011-04-08
Published