cbcvebase.
CVE-2021-3999
published 2022-08-24

CVE-2021-3999: A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the buffer is exactly 1. A…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the buffer is exactly 1. A local attacker who can control the input buffer and size passed to getcwd() in a setuid program could use this flaw to potentially execute arbitrary code and escalate their privileges on the system.

Affected

17 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianglibc< glibc 2.33-4 (bookworm)glibc 2.33-4 (bookworm)
eglibceglibc>= 0 < 2.19-0ubuntu6.15+esm32.19-0ubuntu6.15+esm3
gnuglibc< 2.312.31
gnuglibc
gnuglibc>= 0 < 2.31-13+deb11u42.31-13+deb11u4
gnuglibc>= 0 < 2.33-42.33-4
gnuglibc>= 0 < 2.33-42.33-4
gnuglibc>= 0 < 2.33-42.33-4
gnuglibc>= 0 < 2.27-3ubuntu1.52.27-3ubuntu1.5
gnuglibc>= 0 < 2.31-0ubuntu9.72.31-0ubuntu9.7
gnuglibc>= 0 < 2.23-0ubuntu11.3+esm12.23-0ubuntu11.3+esm1
gnuglibc>= 0 < 2.23-0ubuntu11.3+esm62.23-0ubuntu11.3+esm6
gnuglibc>= 0 < 2.27-3ubuntu1.6+esm22.27-3ubuntu1.6+esm2
msrccm1_glibc_2.28-24_on_cbl_mariner_1.0
paloaltopan-os

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL