← Back

CVE-2011-2702

nvd nist
Published: Oct 27, 2014Modified: May 6, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Integer signedness error in Glibc before 2.13 and eglibc before 2.13, when using Supplemental Streaming SIMD Extensions 3 (SSSE3) optimization, allows context-dependent attackers to execute arbitrary code via a negative length parameter to (1) memcpy-ssse3-rep.S, (2) memcpy-ssse3.S, or (3) memset-sse2.S in sysdeps/i386/i686/multiarch/, which triggers an out-of-bounds read, as demonstrated using the memcpy function.

Affected (4)

Products: Gnu: Glibc, Eglibc
2 products
Glibc
Eglibc
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Gnu
Up to 2.12.2
Version 2.12.1
Version 2.12
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.12

References (16)

Timeline

No history available yet.