CVE-2020-35357
published 2023-08-22CVE-2020-35357: A buffer overflow can occur when calculating the quantile value using the Statistics Library of GSL (GNU Scientific Library), versions 2.5 and 2.6. Processing…
PriorityP431medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.88%
55.7th percentile
A buffer overflow can occur when calculating the quantile value using the Statistics Library of GSL (GNU Scientific Library), versions 2.5 and 2.6. Processing a maliciously crafted input data for gsl_stats_quantile_from_sorted_data of the library may lead to unexpected application termination or arbitrary code execution.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | gsl | < gsl 2.7.1+dfsg-5+deb12u1 (bookworm) | gsl 2.7.1+dfsg-5+deb12u1 (bookworm) |
| gnu | gnu_scientific_library | — | — |
| gnu | gnu_scientific_library | — | — |
| msrc | azl3_gsl_2.8-1_on_azure_linux_3.0 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNU Scientific Library vulnerability
vendor_ubuntu·2023-11-07
CVE-2020-35357 GNU Scientific Library vulnerability
Title: GNU Scientific Library vulnerability
Summary: GNU Scientific Library could be made to crash or execute arbitrary code if it
received specially crafted input.
It was discovered that GNU Scientific Library incorrectly handled certain
inputs. If a user or an automated system were tricked into opening a specially
crafted input file, a remote attacker could possibly use this issue to cause a
denial of service or execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
gsl: Stack buffer overflow in gsl_stats_quantile_from_sorted_data
vendor_redhat·2023-08-22·CVSS 6.5
CVE-2020-35357 [MEDIUM] CWE-119 gsl: Stack buffer overflow in gsl_stats_quantile_from_sorted_data
gsl: Stack buffer overflow in gsl_stats_quantile_from_sorted_data
A buffer overflow can occur when calculating the quantile value using the Statistics Library of GSL (GNU Scientific Library), versions 2.5 and 2.6. Processing a maliciously crafted input data for gsl_stats_quantile_from_sorted_data of the library may lead to unexpected application termination or arbitrary code execution.
A stack buffer overflow flaw was found in the gsl package due to a lack of validation of the user controlled fraction parameter. This issue may allow an attacker to craft malicious input, leading to a segmentation fault and further Denial of Service. Since the buffer overflow happens when reading data from the input array, it's very unlikely to achieve arbitrary code execution using this flaw.
Package: gs
Microsoft
A buffer overflow can occur when calculating the quantile value using the Statistics Library of GSL (GNU Scientific Library), versions 2.5 and 2.6. Processing a maliciously crafted input data for gsl_
vendor_msrc·2023-08-08·CVSS 6.5
CVE-2020-35357 [MEDIUM] CWE-120 A buffer overflow can occur when calculating the quantile value using the Statistics Library of GSL (GNU Scientific Library), versions 2.5 and 2.6. Processing a maliciously crafted input data for gsl_
A buffer overflow can occur when calculating the quantile value using the Statistics Library of GSL (GNU Scientific Library), versions 2.5 and 2.6. Processing a maliciously crafted input data for gsl_stats_quantile_from_sorted_data of the library may lead to unexpected application termination or arbitrary code execution.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in
Debian
CVE-2020-35357: gsl - A buffer overflow can occur when calculating the quantile value using the Statis...
vendor_debian·2020·CVSS 6.5
CVE-2020-35357 [MEDIUM] CVE-2020-35357: gsl - A buffer overflow can occur when calculating the quantile value using the Statis...
A buffer overflow can occur when calculating the quantile value using the Statistics Library of GSL (GNU Scientific Library), versions 2.5 and 2.6. Processing a maliciously crafted input data for gsl_stats_quantile_from_sorted_data of the library may lead to unexpected application termination or arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.7.1+dfsg-5+deb12u1)
bullseye: resolved (fixed in 2.6+dfsg-2+deb11u1)
forky: resolved (fixed in 2.7.1+dfsg-6)
sid: resolved (fixed in 2.7.1+dfsg-6)
trixie: resolved (fixed in 2.7.1+dfsg-6)
GHSA
GHSA-xp4h-43w8-c7qr: A buffer overflow can occur when calculating the quantile value using the Statistics Library of GSL (GNU Scientific Library), versions 2
ghsa_unreviewed·2023-08-22
CVE-2020-35357 [MEDIUM] CWE-120 GHSA-xp4h-43w8-c7qr: A buffer overflow can occur when calculating the quantile value using the Statistics Library of GSL (GNU Scientific Library), versions 2
A buffer overflow can occur when calculating the quantile value using the Statistics Library of GSL (GNU Scientific Library), versions 2.5 and 2.6. Processing a maliciously crafted input data for gsl_stats_quantile_from_sorted_data of the library may lead to unexpected application termination or arbitrary code execution.
OSV
CVE-2020-35357: A buffer overflow can occur when calculating the quantile value using the Statistics Library of GSL (GNU Scientific Library), versions 2
osv·2023-08-22·CVSS 6.5
CVE-2020-35357 [MEDIUM] CVE-2020-35357: A buffer overflow can occur when calculating the quantile value using the Statistics Library of GSL (GNU Scientific Library), versions 2
A buffer overflow can occur when calculating the quantile value using the Statistics Library of GSL (GNU Scientific Library), versions 2.5 and 2.6. Processing a maliciously crafted input data for gsl_stats_quantile_from_sorted_data of the library may lead to unexpected application termination or arbitrary code execution.
No detection rules found.
No public exploits indexed.
https://git.savannah.gnu.org/cgit/gsl.git/commit/?id=989a193268b963aa1047814f7f1402084fb7d859https://lists.debian.org/debian-lts-announce/2023/09/msg00023.htmlhttps://savannah.gnu.org/bugs/?59624https://git.savannah.gnu.org/cgit/gsl.git/commit/?id=989a193268b963aa1047814f7f1402084fb7d859https://lists.debian.org/debian-lts-announce/2023/09/msg00023.htmlhttps://lists.debian.org/debian-lts-announce/2024/12/msg00006.htmlhttps://savannah.gnu.org/bugs/?59624
2023-08-22
Published