CVE-2022-23219
published 2022-01-14CVE-2022-23219: The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack…
PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.21%
89.9th percentile
The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | glibc | < glibc 2.33-3 (bookworm) | glibc 2.33-3 (bookworm) |
| gnu | glibc | < 2.31 | 2.31 |
| gnu | glibc | >= 0 < 2.31-13+deb11u3 | 2.31-13+deb11u3 |
| gnu | glibc | >= 0 < 2.33-3 | 2.33-3 |
| gnu | glibc | >= 0 < 2.33-3 | 2.33-3 |
| gnu | glibc | >= 0 < 2.33-3 | 2.33-3 |
| gnu | glibc | >= 0 < 2.27-3ubuntu1.5 | 2.27-3ubuntu1.5 |
| gnu | glibc | >= 0 < 2.31-0ubuntu9.7 | 2.31-0ubuntu9.7 |
| gnu | glibc | >= 0 < 2.23-0ubuntu11.3+esm1 | 2.23-0ubuntu11.3+esm1 |
| msrc | cbl2_glibc_2.35-1_on_cbl_mariner_2.0 | — | — |
| oracle | communications_cloud_native_core_binding_support_function | — | — |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | — | — |
| oracle | communications_cloud_native_core_network_repository_function | — | — |
| oracle | communications_cloud_native_core_network_repository_function | — | — |
| oracle | communications_cloud_native_core_security_edge_protection_proxy | — | — |
| oracle | communications_cloud_native_core_unified_data_repository | — | — |
| oracle | enterprise_operations_monitor | — | — |
| oracle | enterprise_operations_monitor | — | — |
| oracle | enterprise_operations_monitor | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Oracle Fujitsu M10-1 prior XCP2411/XCP3111/XCP4011 XCP Firmware buffer overflow (EUVD-2022-28308 / Nessus ID 239848)
vuldb·2026-04-30·CVSS 9.8
CVE-2022-23219 [CRITICAL] Oracle Fujitsu M10-1 prior XCP2411/XCP3111/XCP4011 XCP Firmware buffer overflow (EUVD-2022-28308 / Nessus ID 239848)
A vulnerability marked as very critical has been reported in Oracle Fujitsu M10-1, Fujitsu M10-4, Fujitsu M10-4S, Fujitsu M12-1, Fujitsu M12-2 and Fujitsu M12-2S. This affects an unknown function of the component XCP Firmware. The manipulation leads to buffer overflow.
This vulnerability is documented as CVE-2022-23219. The attack can be initiated remotely. There is not any exploit available.
OSV
glibc vulnerabilities
osv·2022-03-07·CVSS 7.8
CVE-2021-3999 [HIGH] glibc vulnerabilities
glibc vulnerabilities
USN-5310-1 fixed several vulnerabilities in GNU. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that the GNU C library getcwd function incorrectly
handled buffers. An attacker could use this issue to cause the GNU C
Library to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2021-3999)
It was discovered that the GNU C Library sunrpc module incorrectly handled
buffer lengths. An attacker could possibly use this issue to cause the GNU
C Library to crash, resulting in a denial of service. (CVE-2022-23218,
CVE-2022-23219)
OSV
glibc vulnerabilities
osv·2022-03-01·CVSS 5.9
CVE-2016-10228 [MEDIUM] glibc vulnerabilities
glibc vulnerabilities
Jan Engelhardt, Tavis Ormandy, and others discovered that the GNU C Library
iconv feature incorrectly handled certain input sequences. An attacker
could possibly use this issue to cause the GNU C Library to hang or crash,
resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS
and Ubuntu 20.04 LTS. (CVE-2016-10228, CVE-2019-25013, CVE-2020-27618,
CVE-2020-29562, CVE-2021-3326)
Jason Royes and Samuel Dytrych discovered that the GNU C Library
incorrectly handled signed comparisons on ARMv7 targets. A remote attacker
could use this issue to cause the GNU C Library to crash, resulting in a
denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-6096)
It was discovered that the
GHSA
GHSA-fhxm-4mc9-6jf5: The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2
ghsa_unreviewed·2022-01-15
CVE-2022-23219 [CRITICAL] CWE-120 GHSA-fhxm-4mc9-6jf5: The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2
The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.
OSV
CVE-2022-23219: The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2
osv·2022-01-14·CVSS 9.8
CVE-2022-23219 [CRITICAL] CVE-2022-23219: The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2
The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.
CISA ICS
Siemens SIMATIC MV500
cisa_ics·2023-11-16·CVSS 9.8
[CRITICAL] Siemens SIMATIC MV500
ICS Advisory
##
Siemens SIMATIC MV500
Release DateNovember 16, 2023
Alert CodeICSA-23-320-13
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC MV500
- Vulnerabilities: Classic Buffer Overflow, NULL Pointer Dereference, Improper Authentication, Inefficient Regular Expression Complexity, Excessive Iteration, Out-of-bounds Write
## 2. RISK EVALUATION
Succe
CISA ICS
Siemens SIMATIC S7-1500 TM MFP BIOS
cisa_ics·2023-06-15·CVSS 5.9
[MEDIUM] Siemens SIMATIC S7-1500 TM MFP BIOS
ICS Advisory
##
Siemens SIMATIC S7-1500 TM MFP BIOS
Release DateJune 15, 2023
Alert CodeICSA-23-166-10
## As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely / low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 TM MFP
- Vulnerabilities: Improper Input Validation, Out-of-bounds Read, Use After Free, Out-of-bounds Write, Infinite Loop, Reachable Assertion, Off-by-one Error, Incorrect Default Permissions, Double Fr
Oracle
Oracle Oracle Systems Risk Matrix: XCP Firmware (glibc) — CVE-2022-23219
vendor_oracle·2023-01-15·CVSS 9.8
CVE-2022-23219 [CRITICAL] Oracle Oracle Systems Risk Matrix: XCP Firmware (glibc) — CVE-2022-23219
Oracle Oracle Systems Risk Matrix: XCP Firmware (glibc) vulnerability
CVE: CVE-2022-23219
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Oracle
Oracle Oracle Communications Risk Matrix: Routing (glibc) — CVE-2022-23219
vendor_oracle·2022-10-15·CVSS 7.0
CVE-2022-23219 [CRITICAL] Oracle Oracle Communications Risk Matrix: Routing (glibc) — CVE-2022-23219
Oracle Oracle Communications Risk Matrix: Routing (glibc) vulnerability
CVE: CVE-2022-23219
CVSS: 7.0
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle Communications Risk Matrix: BSF (glibc) — CVE-2022-23219
vendor_oracle·2022-07-15·CVSS 9.8
CVE-2022-23219 [CRITICAL] Oracle Oracle Communications Risk Matrix: BSF (glibc) — CVE-2022-23219
Oracle Oracle Communications Risk Matrix: BSF (glibc) vulnerability
CVE: CVE-2022-23219
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2022-03-07·CVSS 7.8
CVE-2022-23218 [HIGH] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in GNU C Library.
USN-5310-1 fixed several vulnerabilities in GNU. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that the GNU C library getcwd function incorrectly
handled buffers. An attacker could use this issue to cause the GNU C
Library to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2021-3999)
It was discovered that the GNU C Library sunrpc module incorrectly handled
buffer lengths. An attacker could possibly use this issue to cause the GNU
C Library to crash, resulting in a denial of service. (CVE-2022-23218,
CVE-2022-23219)
Instructions: After a standard system update you need to reboot your com
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2022-03-01·CVSS 5.9
CVE-2021-3999 [MEDIUM] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in GNU C Library.
Jan Engelhardt, Tavis Ormandy, and others discovered that the GNU C Library
iconv feature incorrectly handled certain input sequences. An attacker
could possibly use this issue to cause the GNU C Library to hang or crash,
resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS
and Ubuntu 20.04 LTS. (CVE-2016-10228, CVE-2019-25013, CVE-2020-27618,
CVE-2020-29562, CVE-2021-3326)
Jason Royes and Samuel Dytrych discovered that the GNU C Library
incorrectly handled signed comparisons on ARMv7 targets. A remote attacker
could use this issue to cause the GNU C Library to crash, resulting in a
denial of service, or possibly execute arbitrary code. This issue only
affected Ubunt
Microsoft
The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length which may r
vendor_msrc·2022-01-11·CVSS 9.8
CVE-2022-23219 [CRITICAL] CWE-120 The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length which may r
The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length which may result in a buffer overflow potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work wh
Debian
CVE-2022-23219: glibc - The deprecated compatibility function clnt_create in the sunrpc module of the GN...
vendor_debian·2022·CVSS 9.8
CVE-2022-23219 [CRITICAL] CVE-2022-23219: glibc - The deprecated compatibility function clnt_create in the sunrpc module of the GN...
The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.33-3)
bullseye: resolved (fixed in 2.31-13+deb11u3)
forky: resolved (fixed in 2.33-3)
sid: resolved (fixed in 2.33-3)
trixie: resolved (fixed in 2.33-3)
Red Hat
glibc: Stack-based buffer overflow in sunrpc clnt_create via a long pathname
vendor_redhat·2017-12-03·CVSS 9.8
CVE-2022-23219 [CRITICAL] CWE-787 glibc: Stack-based buffer overflow in sunrpc clnt_create via a long pathname
glibc: Stack-based buffer overflow in sunrpc clnt_create via a long pathname
The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.
A stack based buffer-overflow vulnerability was found in the deprecated compatibility function clnt_create() in the sunrpc's clnt_gen.c module of the GNU C Library (aka glibc) through 2.34. This vulnerability copies its hostname argument onto the stack without validating its length, which may result in a buffer overflow, potentially resulting in a deni
No detection rules found.
No public exploits indexed.
https://lists.debian.org/debian-lts-announce/2022/10/msg00021.htmlhttps://security.gentoo.org/glsa/202208-24https://sourceware.org/bugzilla/show_bug.cgi?id=22542https://www.oracle.com/security-alerts/cpujul2022.htmlhttps://lists.debian.org/debian-lts-announce/2022/10/msg00021.htmlhttps://security.gentoo.org/glsa/202208-24https://sourceware.org/bugzilla/show_bug.cgi?id=22542https://www.oracle.com/security-alerts/cpujul2022.html
2022-01-14
Published