CVE-2020-1751
published 2020-04-17CVE-2020-1751: An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtrace function did not…
PriorityP431high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.54%
41.6th percentile
An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtrace function did not properly check the array bounds when storing the frame address, resulting in a denial of service or potential code execution. The highest threat from this vulnerability is to system availability.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | glibc | < glibc 2.30-3 (bookworm) | glibc 2.30-3 (bookworm) |
| gnu | glibc | < 2.31 | 2.31 |
| gnu | glibc | >= 0 < 2.30-3 | 2.30-3 |
| gnu | glibc | >= 0 < 2.30-3 | 2.30-3 |
| gnu | glibc | >= 0 < 2.30-3 | 2.30-3 |
| gnu | glibc | >= 0 < 2.30-3 | 2.30-3 |
| gnu | glibc | >= 0 < 2.23-0ubuntu11.2 | 2.23-0ubuntu11.2 |
| gnu | glibc | >= 0 < 2.27-3ubuntu1.2 | 2.27-3ubuntu1.2 |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_glibc_2.28-12_on_cbl_mariner_1.0 | — | — |
| red_hat | glibc | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.9MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:C
osv7.0HIGH
vendor_msrc7.0HIGH
vendor_ubuntu5.9MEDIUM
vendor_debian5.1MEDIUM
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2020-07-06·CVSS 5.9
CVE-2017-12133 [MEDIUM] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in GNU C Library.
Florian Weimer discovered that the GNU C Library incorrectly handled
certain memory operations. A remote attacker could use this issue to cause
the GNU C Library to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2017-12133)
It was discovered that the GNU C Library incorrectly handled certain
SSE2-optimized memmove operations. A remote attacker could use this issue
to cause the GNU C Library to crash, resulting in a denial of service, or
possibly execute arbitrary code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2017-18269)
It was discovered that the GNU C Library incorrectly handled certain
pathname operati
Microsoft
An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically the backtrace function did not properly check the array bounds when storin
vendor_msrc·2020-04-14·CVSS 7.0
CVE-2020-1751 [MEDIUM] CWE-787 An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically the backtrace function did not properly check the array bounds when storin
An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically the backtrace function did not properly check the array bounds when storing the frame address resulting in a denial of service or potential code execution. The highest threat from this vulnerability is to system availability.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we
Red Hat
glibc: array overflow in backtrace functions for powerpc
vendor_redhat·2020-01-20·CVSS 5.1
CVE-2020-1751 [MEDIUM] CWE-787 glibc: array overflow in backtrace functions for powerpc
glibc: array overflow in backtrace functions for powerpc
An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtrace function did not properly check the array bounds when storing the frame address, resulting in a denial of service or potential code execution. The highest threat from this vulnerability is to system availability.
An out-of-bounds write vulnerability was found in glibc when handling signal trampolines on PowerPC. The backtrace function did not properly check the array bounds when storing the frame address resulting in a denial of service or potential code execution. The highest threat from this vulnerability is to system availability.
Statement: This flaw did not affect the versions of `glibc`
Debian
CVE-2020-1751: glibc - An out-of-bounds write vulnerability was found in glibc before 2.31 when handlin...
vendor_debian·2020·CVSS 5.1
CVE-2020-1751 [MEDIUM] CVE-2020-1751: glibc - An out-of-bounds write vulnerability was found in glibc before 2.31 when handlin...
An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtrace function did not properly check the array bounds when storing the frame address, resulting in a denial of service or potential code execution. The highest threat from this vulnerability is to system availability.
Scope: local
bookworm: resolved (fixed in 2.30-3)
bullseye: resolved (fixed in 2.30-3)
forky: resolved (fixed in 2.30-3)
sid: resolved (fixed in 2.30-3)
trixie: resolved (fixed in 2.30-3)
GHSA
GHSA-22j8-wpwh-4rrr: An out-of-bounds write vulnerability was found in glibc before 2
ghsa_unreviewed·2022-05-24
CVE-2020-1751 [MEDIUM] CWE-787 GHSA-22j8-wpwh-4rrr: An out-of-bounds write vulnerability was found in glibc before 2
An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtrace function did not properly check the array bounds when storing the frame address, resulting in a denial of service or potential code execution. The highest threat from this vulnerability is to system availability.
OSV
glibc vulnerabilities
osv·2020-07-06·CVSS 5.9
CVE-2017-12133 [MEDIUM] glibc vulnerabilities
glibc vulnerabilities
Florian Weimer discovered that the GNU C Library incorrectly handled
certain memory operations. A remote attacker could use this issue to cause
the GNU C Library to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2017-12133)
It was discovered that the GNU C Library incorrectly handled certain
SSE2-optimized memmove operations. A remote attacker could use this issue
to cause the GNU C Library to crash, resulting in a denial of service, or
possibly execute arbitrary code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2017-18269)
It was discovered that the GNU C Library incorrectly handled certain
pathname operations. A remote attacker could use this issue to cause the
GNU C Library to cras
OSV
CVE-2020-1751: An out-of-bounds write vulnerability was found in glibc before 2
osv·2020-04-17·CVSS 7.0
CVE-2020-1751 [HIGH] CVE-2020-1751: An out-of-bounds write vulnerability was found in glibc before 2
An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtrace function did not properly check the array bounds when storing the frame address, resulting in a denial of service or potential code execution. The highest threat from this vulnerability is to system availability.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-27768 ImageMagick: outside the range of representable values of type 'unsigned int' at MagickCore/quantum-private.h
bugzilla·2020-11-04·CVSS 3.3
CVE-2020-27768 [LOW] CVE-2020-27768 ImageMagick: outside the range of representable values of type 'unsigned int' at MagickCore/quantum-private.h
CVE-2020-27768 ImageMagick: outside the range of representable values of type 'unsigned int' at MagickCore/quantum-private.h
In ImageMagick, there is an outside the range of representable values of type 'unsigned int' at MagickCore/quantum-private.h.
Reference:
https://github.com/ImageMagick/ImageMagick/issues/1751
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/95d4e94e0353e503b71a53f5e6fad173c7c70c90
Discussion:
Acknowledgments:
Name: Suhwan Song (Seoul National University)
---
There are numerous occurrences of this patched in MagickCore/quantum-private.h. Red Hat Product Security marked this as Low severity because although it could potentially lead to an impact to application availability, no specific impact was demonstrated in this case.
---
Statement:
Thi
Bugzilla
CVE-2020-15011 mailman: arbitrary content injection via the private archive login page
bugzilla·2020-06-24·CVSS 4.3
CVE-2020-15011 [MEDIUM] CVE-2020-15011 mailman: arbitrary content injection via the private archive login page
CVE-2020-15011 mailman: arbitrary content injection via the private archive login page
GNU Mailman before 2.1.33 allows arbitrary content injection via the Cgi/private.py private archive login page.
Reference:
https://bugs.launchpad.net/mailman/+bug/1877379
Discussion:
Created mailman tracking bugs for this issue:
Affects: fedora-all [bug 1850688]
---
Upstream patch: https://bazaar.launchpad.net/~mailman-coders/mailman/2.1/revision/1848#Mailman/Cgi/private.py
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-15011
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2021:1751 https://access.redhat.com/errata/RHSA-2021:1751
Bugzilla
CVE-2020-12108 mailman: arbitrary content injection via the options login page
bugzilla·2020-06-19·CVSS 6.5
CVE-2020-12108 [MEDIUM] CVE-2020-12108 mailman: arbitrary content injection via the options login page
CVE-2020-12108 mailman: arbitrary content injection via the options login page
/options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection.
Reference:
http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00036.html
Discussion:
Created mailman tracking bugs for this issue:
Affects: fedora-31 [bug 1848859]
---
Patch:
https://bazaar.launchpad.net/~mailman-coders/mailman/2.1/revision/1844
---
External References:
https://bugs.launchpad.net/mailman/+bug/1873722
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-12108
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2021:1751 https://access.redhat.
Bugzilla
CVE-2020-1751 glibc: array overflow in backtrace functions for powerpc [fedora-all]
bugzilla·2020-03-09·CVSS 5.1
CVE-2020-1751 [MEDIUM] CVE-2020-1751 glibc: array overflow in backtrace functions for powerpc [fedora-all]
CVE-2020-1751 glibc: array overflow in backtrace functions for powerpc [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ve
Bugzilla
CVE-2020-1751 glibc: array overflow in backtrace functions for powerpc
bugzilla·2020-03-05·CVSS 5.1
CVE-2020-1751 [MEDIUM] CVE-2020-1751 glibc: array overflow in backtrace functions for powerpc
CVE-2020-1751 glibc: array overflow in backtrace functions for powerpc
When unwinding through a signal frame the backtrace function on PowerPC didn't check array bounds when storing the frame address.
Reference:
https://sourceware.org/bugzilla/show_bug.cgi?id=25423
Upstream commit:
https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=d93769405996dfc11d216ddbe415946617b5a494
Discussion:
Created glibc tracking bugs for this issue:
Affects: fedora-all [bug 1811589]
---
Statement:
This flaw did not affect the versions of `glibc` as shipped with Red Hat Enterprise Linux 5, 6, and 7, as they did not include the vulnerable code, which was introduced in a later version of the package.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1751https://security.gentoo.org/glsa/202006-04https://security.netapp.com/advisory/ntap-20200430-0002/https://sourceware.org/bugzilla/show_bug.cgi?id=25423https://usn.ubuntu.com/4416-1/https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1751https://security.gentoo.org/glsa/202006-04https://security.netapp.com/advisory/ntap-20200430-0002/https://sourceware.org/bugzilla/show_bug.cgi?id=25423https://usn.ubuntu.com/4416-1/
2020-04-17
Published