CVE-2022-39046
published 2022-08-31CVE-2022-39046: An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a crafted input string larger than 1024 bytes, it reads…
PriorityP427medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
1.55%
72.6th percentile
An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a crafted input string larger than 1024 bytes, it reads uninitialized memory from the heap and prints it to the target log file, potentially revealing a portion of the contents of the heap.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | >= 0 < 2.27-3ubuntu1.6 | 2.27-3ubuntu1.6 |
| gnu | glibc | >= 0 < 2.31-0ubuntu9.9 | 2.31-0ubuntu9.9 |
| gnu | glibc | >= 0 < 2.35-0ubuntu3.1 | 2.35-0ubuntu3.1 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
osv5.3MEDIUM
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f6rj-qrpf-jc34: An issue was discovered in the GNU C Library (glibc) 2
ghsa_unreviewed·2022-09-01
CVE-2022-39046 [MEDIUM] CWE-532 GHSA-f6rj-qrpf-jc34: An issue was discovered in the GNU C Library (glibc) 2
An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a crafted input string larger than 1024 bytes, it reads uninitialized memory from the heap and prints it to the target log file, potentially revealing a portion of the contents of the heap.
OSV
CVE-2022-39046: An issue was discovered in the GNU C Library (glibc) 2
osv·2022-08-31·CVSS 5.3
CVE-2022-39046 [MEDIUM] CVE-2022-39046: An issue was discovered in the GNU C Library (glibc) 2
An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a crafted input string larger than 1024 bytes, it reads uninitialized memory from the heap and prints it to the target log file, potentially revealing a portion of the contents of the heap.
Red Hat
glibc: a crafted input may allow information disclosure
vendor_redhat·2022-08-31·CVSS 7.5
CVE-2022-39046 [HIGH] CWE-20 glibc: a crafted input may allow information disclosure
glibc: a crafted input may allow information disclosure
An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a crafted input string larger than 1024 bytes, it reads uninitialized memory from the heap and prints it to the target log file, potentially revealing a portion of the contents of the heap.
A flaw was found in the glibc package. If the Syslog function is passed a crafted input string larger than 1024 bytes, it reads uninitialized memory from the heap and prints it to the target log file, potentially revealing a portion of the contents of the heap.
Statement: The flaw was introduced in glibc version 2.36.
Package: compat-glibc (Red Hat Enterprise Linux 6) - Not affected
Package: glibc (Red Hat Enterprise Linux 6) - Not affected
Package:
Debian
CVE-2022-39046: glibc - An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog funct...
vendor_debian·2022·CVSS 7.5
CVE-2022-39046 [HIGH] CVE-2022-39046: glibc - An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog funct...
An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a crafted input string larger than 1024 bytes, it reads uninitialized memory from the heap and prints it to the target log file, potentially revealing a portion of the contents of the heap.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Qualys
Qualys TRU Discovers Important Vulnerabilities in GNU C Library’s syslog() | Qualys
blogs_qualys·2024-01-30·CVSS 8.4
CVE-2023-6246 [HIGH] Qualys TRU Discovers Important Vulnerabilities in GNU C Library’s syslog() | Qualys
#### Table of Contents
- Vulnerabilities in GNU C Library:
- Heap-Based Buffer Overflow in __vsyslog_internal() Function (CVE-2023-6246):
- Memory Corruption in qsort() Function:
- Qualys QID Coverage:
- Enhance Your Security Posture with Qualys Vulnerability Management, Detection, and Response (VMDR)
- Discover Vulnerable Assets Using Qualys CyberSecurity Asset Management (CSAM)
- Disclosure Timeline for CVE-2023-6246, CVE-2023-6779 and CVE-2023-6780
- Disclosure Timeline for Out-of-bounds read & write in glibcs qsort()
- Technical Details
The Qualys Threat Research Unit (TRU) has recently unearthed four significant vulnerabilities in the GNU C Library, a cornerstone for countless applications in the Linux environment.
Before diving into the specific details of the vulnerabilities disc
Qualys
Qualys TRU Discovers Important Vulnerabilities in GNU C Library’s syslog()
blogs_qualys·2024-01-30·CVSS 8.4
CVE-2023-6246 [HIGH] Qualys TRU Discovers Important Vulnerabilities in GNU C Library’s syslog()
## Table of Contents
Vulnerabilities in GNU C Library:
Heap-Based Buffer Overflow in __vsyslog_internal() Function (CVE-2023-6246):
Memory Corruption in qsort() Function:
Qualys QID Coverage:
Enhance Your Security Posture with Qualys Vulnerability Management, Detection, and Response (VMDR)
Discover Vulnerable Assets Using Qualys CyberSecurity Asset Management (CSAM)
Disclosure Timeline for CVE-2023-6246, CVE-2023-6779 and CVE-2023-6780
Disclosure Timeline for Out-of-bounds read & write in glibcs qsort()
Technical Details
The Qualys Threat Research Unit (TRU) has recently unearthed four significant vulnerabilities in the GNU C Library, a cornerstone for countless applications in the Linux environment.
Before diving into the specific details of the vulnerabilities discovered by th
http://packetstormsecurity.com/files/176932/glibc-syslog-Heap-Based-Buffer-Overflow.htmlhttp://seclists.org/fulldisclosure/2024/Feb/3http://www.openwall.com/lists/oss-security/2024/01/30/6http://www.openwall.com/lists/oss-security/2024/01/30/8https://security.gentoo.org/glsa/202310-03https://security.netapp.com/advisory/ntap-20221104-0002/https://sourceware.org/bugzilla/show_bug.cgi?id=29536http://packetstormsecurity.com/files/176932/glibc-syslog-Heap-Based-Buffer-Overflow.htmlhttp://seclists.org/fulldisclosure/2024/Feb/3http://www.openwall.com/lists/oss-security/2024/01/30/6http://www.openwall.com/lists/oss-security/2024/01/30/8https://security.gentoo.org/glsa/202310-03https://security.netapp.com/advisory/ntap-20221104-0002/https://sourceware.org/bugzilla/show_bug.cgi?id=29536
2022-08-31
Published