CVE-2014-4043
published 2014-10-06CVE-2014-4043: The posix_spawn_file_actions_addopen function in glibc before 2.20 does not copy its path argument in accordance with the POSIX specification, which allows…
PriorityP336high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.92%
89.2th percentile
The posix_spawn_file_actions_addopen function in glibc before 2.20 does not copy its path argument in accordance with the POSIX specification, which allows context-dependent attackers to trigger use-after-free vulnerabilities.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.19-2 (bookworm) | glibc 2.19-2 (bookworm) |
| eglibc | eglibc | >= 0 < 2.19-0ubuntu6.1 | 2.19-0ubuntu6.1 |
| gnu | glibc | <= 2.19 | — |
| gnu | glibc | >= 0 < 2.19-2 | 2.19-2 |
| gnu | glibc | >= 0 < 2.19-2 | 2.19-2 |
| gnu | glibc | >= 0 < 2.19-2 | 2.19-2 |
| gnu | glibc | >= 0 < 2.19-2 | 2.19-2 |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7fjc-2773-f7m5: The posix_spawn_file_actions_addopen function in glibc before 2
ghsa_unreviewed·2022-05-14
CVE-2014-4043 [HIGH] CWE-94 GHSA-7fjc-2773-f7m5: The posix_spawn_file_actions_addopen function in glibc before 2
The posix_spawn_file_actions_addopen function in glibc before 2.20 does not copy its path argument in accordance with the POSIX specification, which allows context-dependent attackers to trigger use-after-free vulnerabilities.
OSV
CVE-2014-4043: The posix_spawn_file_actions_addopen function in glibc before 2
osv·2014-10-06·CVSS 7.5
CVE-2014-4043 [HIGH] CVE-2014-4043: The posix_spawn_file_actions_addopen function in glibc before 2
The posix_spawn_file_actions_addopen function in glibc before 2.20 does not copy its path argument in accordance with the POSIX specification, which allows context-dependent attackers to trigger use-after-free vulnerabilities.
OSV
eglibc vulnerabilities
osv·2014-08-04·CVSS 7.5
CVE-2013-4357 [HIGH] eglibc vulnerabilities
eglibc vulnerabilities
Maksymilian Arciemowicz discovered that the GNU C Library incorrectly
handled the getaddrinfo() function. An attacker could use this issue to
cause a denial of service. This issue only affected Ubuntu 10.04 LTS.
(CVE-2013-4357)
It was discovered that the GNU C Library incorrectly handled the
getaddrinfo() function. An attacker could use this issue to cause a denial
of service. This issue only affected Ubuntu 10.04 LTS and Ubuntu 12.04 LTS.
(CVE-2013-4458)
Stephane Chazelas discovered that the GNU C Library incorrectly handled
locale environment variables. An attacker could use this issue to possibly
bypass certain restrictions such as the ForceCommand restrictions in
OpenSSH. (CVE-2014-0475)
David Reid, Glyph Lefkowitz, and Alex Gaynor discovered that the GNU C
L
Ubuntu
GNU C Library regression
vendor_ubuntu·2014-09-08·CVSS 7.5
CVE-2013-4357 [HIGH] GNU C Library regression
Title: GNU C Library regression
Summary: USN-2306-1 introduced a regression in the GNU C Library.
USN-2306-1 fixed vulnerabilities in the GNU C Library. On Ubuntu 10.04 LTS,
the fix for CVE-2013-4357 introduced a memory leak in getaddrinfo. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Maksymilian Arciemowicz discovered that the GNU C Library incorrectly
handled the getaddrinfo() function. An attacker could use this issue to
cause a denial of service. This issue only affected Ubuntu 10.04 LTS.
(CVE-2013-4357)
It was discovered that the GNU C Library incorrectly handled the
getaddrinfo() function. An attacker could use this issue to cause a denial
of service. This issue only affected Ubuntu 10.04 LTS and Ubuntu 12.04 LTS.
(CVE-2013-4458)
Ubuntu
GNU C Library regression
vendor_ubuntu·2014-08-05·CVSS 7.5
[HIGH] GNU C Library regression
Title: GNU C Library regression
Summary: USN-2306-1 introduced a regression in the GNU C Library.
USN-2306-1 fixed vulnerabilities in the GNU C Library. On Ubuntu 10.04 LTS,
the security update cause a regression in certain environments that use
the Name Service Caching Daemon (nscd), such as those configured for LDAP
or MySQL authentication. In these environments, the nscd daemon may need
to be stopped manually for name resolution to resume working so that
updates can be downloaded, including environments configured for unattended
updates.
We apologize for the inconvenience.
Original advisory details:
Maksymilian Arciemowicz discovered that the GNU C Library incorrectly
handled the getaddrinfo() function. An attacker could use this issue to
cause a denial of service. This issue only
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2014-08-04·CVSS 7.5
CVE-2013-4357 [HIGH] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in the GNU C Library.
Maksymilian Arciemowicz discovered that the GNU C Library incorrectly
handled the getaddrinfo() function. An attacker could use this issue to
cause a denial of service. This issue only affected Ubuntu 10.04 LTS.
(CVE-2013-4357)
It was discovered that the GNU C Library incorrectly handled the
getaddrinfo() function. An attacker could use this issue to cause a denial
of service. This issue only affected Ubuntu 10.04 LTS and Ubuntu 12.04 LTS.
(CVE-2013-4458)
Stephane Chazelas discovered that the GNU C Library incorrectly handled
locale environment variables. An attacker could use this issue to possibly
bypass certain restrictions such as the ForceCommand restrictions in
OpenSSH. (CVE-201
Red Hat
glibc: posix_spawn_file_actions_addopen fails to copy the path argument
vendor_redhat·2014-06-11·CVSS 7.5
CVE-2014-4043 [HIGH] glibc: posix_spawn_file_actions_addopen fails to copy the path argument
glibc: posix_spawn_file_actions_addopen fails to copy the path argument
The posix_spawn_file_actions_addopen function in glibc before 2.20 does not copy its path argument in accordance with the POSIX specification, which allows context-dependent attackers to trigger use-after-free vulnerabilities.
Package: glibc (Red Hat Enterprise Linux 4) - Will not fix
Package: glibc (Red Hat Enterprise Linux 5) - Will not fix
Package: glibc (Red Hat Enterprise Linux 6) - Will not fix
Package: glibc (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2014-4043: glibc - The posix_spawn_file_actions_addopen function in glibc before 2.20 does not copy...
vendor_debian·2014·CVSS 7.5
CVE-2014-4043 [HIGH] CVE-2014-4043: glibc - The posix_spawn_file_actions_addopen function in glibc before 2.20 does not copy...
The posix_spawn_file_actions_addopen function in glibc before 2.20 does not copy its path argument in accordance with the POSIX specification, which allows context-dependent attackers to trigger use-after-free vulnerabilities.
Scope: local
bookworm: resolved (fixed in 2.19-2)
bullseye: resolved (fixed in 2.19-2)
forky: resolved (fixed in 2.19-2)
sid: resolved (fixed in 2.19-2)
trixie: resolved (fixed in 2.19-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-4043 glibc: posix_spawn_file_actions_addopen fails to copy the path argument [fedora-all]
bugzilla·2014-06-16·CVSS 7.5
CVE-2014-4043 [HIGH] CVE-2014-4043 glibc: posix_spawn_file_actions_addopen fails to copy the path argument [fedora-all]
CVE-2014-4043 glibc: posix_spawn_file_actions_addopen fails to copy the path argument [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this is
Bugzilla
CVE-2014-4043 glibc: posix_spawn_file_actions_addopen fails to copy the path argument
bugzilla·2014-06-13·CVSS 7.5
CVE-2014-4043 [HIGH] CVE-2014-4043 glibc: posix_spawn_file_actions_addopen fails to copy the path argument
CVE-2014-4043 glibc: posix_spawn_file_actions_addopen fails to copy the path argument
posix_spawn_file_actions_addopen in glibc fails to copy the path argument.
Per the specification (http://pubs.opengroup.org/onlinepubs/000095399/functions/posix_spawn_file_actions_addclose.html) it is supposed to.
The result of not copying is that programs can easily trigger use-after-free bugs,
or other situations where the path is mutated. The following program demonstrates this issue:
#include
#include
#include
#include
#include
#include
#include
#include
#include
extern char *const *environ;
int main() {
int res;
posix_spawn_file_actions_t fa;
posix_spawn_file_actions_init(&fa);
char *orig_path = "/tmp/afddsa";
char *path = malloc(strlen(orig_path) + 1);
strcpy(path, orig_path);
path[strlen(orig
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00012.htmlhttp://packetstormsecurity.com/files/153278/WAGO-852-Industrial-Managed-Switch-Series-Code-Execution-Hardcoded-Credentials.htmlhttp://packetstormsecurity.com/files/154361/Cisco-Device-Hardcoded-Credentials-GNU-glibc-BusyBox.htmlhttp://seclists.org/fulldisclosure/2019/Jun/18http://seclists.org/fulldisclosure/2019/Sep/7http://www.mandriva.com/security/advisories?name=MDVSA-2014:152http://www.securityfocus.com/bid/68006https://bugzilla.redhat.com/show_bug.cgi?id=1109263https://exchange.xforce.ibmcloud.com/vulnerabilities/93784https://seclists.org/bugtraq/2019/Jun/14https://seclists.org/bugtraq/2019/Sep/7https://security.gentoo.org/glsa/201503-04https://sourceware.org/bugzilla/show_bug.cgi?id=17048https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=blobdiff%3Bf=ChangeLog%3Bh=3020b9ac232315df362521aeaf85f21cb9926db8%3Bhp=d86e73963dd9fb5e21b1a28326630337226812aa%3Bhb=89e435f3559c53084498e9baad22172b64429362%3Bhpb=c3a2ebe1f7541cc35937621e08c28ff88afd0845https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=blobdiff%3Bf=posix/spawn_faction_addopen.c%3Bh=40800b8e6e81341501c0fb8a91009529e2048dec%3Bhp=47f62425b696a4fdd511b2a057746322eb6518db%3Bhb=89e435f3559c53084498e9baad22172b64429362%3Bhpb=c3a2ebe1f7541cc35937621e08c28ff88afd0845https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=89e435f3559c53084498e9baad22172b64429362http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00012.htmlhttp://packetstormsecurity.com/files/153278/WAGO-852-Industrial-Managed-Switch-Series-Code-Execution-Hardcoded-Credentials.htmlhttp://packetstormsecurity.com/files/154361/Cisco-Device-Hardcoded-Credentials-GNU-glibc-BusyBox.htmlhttp://seclists.org/fulldisclosure/2019/Jun/18http://seclists.org/fulldisclosure/2019/Sep/7http://www.mandriva.com/security/advisories?name=MDVSA-2014:152http://www.securityfocus.com/bid/68006https://bugzilla.redhat.com/show_bug.cgi?id=1109263https://exchange.xforce.ibmcloud.com/vulnerabilities/93784https://seclists.org/bugtraq/2019/Jun/14https://seclists.org/bugtraq/2019/Sep/7https://security.gentoo.org/glsa/201503-04https://sourceware.org/bugzilla/show_bug.cgi?id=17048https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=blobdiff%3Bf=ChangeLog%3Bh=3020b9ac232315df362521aeaf85f21cb9926db8%3Bhp=d86e73963dd9fb5e21b1a28326630337226812aa%3Bhb=89e435f3559c53084498e9baad22172b64429362%3Bhpb=c3a2ebe1f7541cc35937621e08c28ff88afd0845https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=blobdiff%3Bf=posix/spawn_faction_addopen.c%3Bh=40800b8e6e81341501c0fb8a91009529e2048dec%3Bhp=47f62425b696a4fdd511b2a057746322eb6518db%3Bhb=89e435f3559c53084498e9baad22172b64429362%3Bhpb=c3a2ebe1f7541cc35937621e08c28ff88afd0845https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=89e435f3559c53084498e9baad22172b64429362
2014-10-06
Published