CVE-2014-9761

CWE-119Buffer Overflow12 documents8 sources
Severity
9.8CRITICAL
EPSS
3.8%
top 11.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 19
Latest updateMay 14

Description

Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long argument to the (1) nan, (2) nanf, or (3) nanl function.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages9 packages

Debianglibc< 2.23-1+3
Ubuntueglibc< 2.19-0ubuntu6.9
NVDgnu/glibc2.22

Also affects: Fedora 23, Ubuntu Linux 12.04, 14.04, 15.10

🔴Vulnerability Details

4
GHSA
GHSA-vf4r-x8xm-qwqj: Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 22022-05-14
OSV
eglibc, glibc regression2016-05-26
CVEList
CVE-2014-9761: Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 22016-04-19
OSV
CVE-2014-9761: Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 22016-04-19

📋Vendor Advisories

4
Ubuntu
GNU C Library regression2016-05-26
Ubuntu
GNU C Library vulnerabilities2016-05-25
Red Hat
glibc: Unbounded stack allocation in nan* functions2014-05-19
Debian
CVE-2014-9761: glibc - Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) ...2014

💬Community

2
Bugzilla
CVE-2014-9761 glibc: Unbounded stack allocation in nan* functions [fedora-all]2016-01-20
Bugzilla
CVE-2014-9761 glibc: Unbounded stack allocation in nan* functions2016-01-20
CVE-2014-9761 (CRITICAL CVSS 9.8) | Multiple stack-based buffer overflo | cvebase.io