CVE-2023-0687
published 2023-02-06CVE-2023-0687: A vulnerability was found in GNU C Library 2.38. It has been declared as critical. This vulnerability affects the function __monstartup of the file gmon.c of…
PriorityP353critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.10%
62.3th percentile
A vulnerability was found in GNU C Library 2.38. It has been declared as critical. This vulnerability affects the function __monstartup of the file gmon.c of the component Call Graph Monitor. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. VDB-220246 is the identifier assigned to this vulnerability. NOTE: The real existence of this vulnerability is still doubted at the moment. The inputs that induce this vulnerability are basically addresses of the running application that is built with gmon enabled. It's basically trusted input or input that needs an actual security flaw to be compromised or controlled.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | c_library | — | — |
| gnu | glibc | < 2.38 | 2.38 |
| msrc | cbl2_glibc_2.35-7_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_glibc_2.28-24_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.0MEDIUMAV:A/AC:H/Au:S/C:P/I:P/A:P
vendor_msrc4.6MEDIUM
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5r4p-4pqv-gqhw: A vulnerability was found in GNU C Library 2
ghsa_unreviewed·2023-02-06
CVE-2023-0687 [CRITICAL] CWE-120 GHSA-5r4p-4pqv-gqhw: A vulnerability was found in GNU C Library 2
A vulnerability was found in GNU C Library 2.38. It has been declared as critical. This vulnerability affects the function __monstartup of the file gmon.c of the component Call Graph Monitor. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. VDB-220246 is the identifier assigned to this vulnerability.
Microsoft
A vulnerability was found in GNU C Library 2.38. It has been declared as critical. This vulnerability affects the function __monstartup of the file gmon.c of the component Call Graph Monitor. The mani
vendor_msrc·2023-02-14·CVSS 4.6
CVE-2023-0687 [MEDIUM] CWE-120 A vulnerability was found in GNU C Library 2.38. It has been declared as critical. This vulnerability affects the function __monstartup of the file gmon.c of the component Call Graph Monitor. The mani
A vulnerability was found in GNU C Library 2.38. It has been declared as critical. This vulnerability affects the function __monstartup of the file gmon.c of the component Call Graph Monitor. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. VDB-220246 is the identifier assigned to this vulnerability. NOTE: The real existence of this vulnerability is still doubted at the moment. The inputs that induce this vulnerability are basically addresses of the running application that is built with gmon enabled. It's basically trusted input or input that needs an actual security flaw to be compromised or controlled.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulner
Red Hat
glibc: gmon memory corruption due wrong calculation of required buffer size
vendor_redhat·2023-02-06·CVSS 4.6
CVE-2023-0687 [MEDIUM] CWE-120 glibc: gmon memory corruption due wrong calculation of required buffer size
glibc: gmon memory corruption due wrong calculation of required buffer size
A vulnerability was found in GNU C Library 2.38. It has been declared as critical. This vulnerability affects the function __monstartup of the file gmon.c of the component Call Graph Monitor. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. VDB-220246 is the identifier assigned to this vulnerability. NOTE: The real existence of this vulnerability is still doubted at the moment. The inputs that induce this vulnerability are basically addresses of the running application that is built with gmon enabled. It's basically trusted input or input that needs an actual security flaw to be compromised or controlled.
A vulnerability was found in the GNU C Library. This flaw aff
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://patchwork.sourceware.org/project/glibc/patch/20230204114138.5436-1-leo%40yuriev.ru/https://sourceware.org/bugzilla/show_bug.cgi?id=29444https://vuldb.com/?ctiid.220246https://vuldb.com/?id.220246https://patchwork.sourceware.org/project/glibc/patch/20230204114138.5436-1-leo%40yuriev.ru/https://sourceware.org/bugzilla/show_bug.cgi?id=29444https://vuldb.com/?ctiid.220246https://vuldb.com/?id.220246
2023-02-06
Published