7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
Affected (73)
Products: Netapp: Bootstrap Os, H410c Firmware, H300s Firmware, H500s Firmware, H700s Firmware, H410s Firmware, Ontap Select Deploy Administration Utility · Siemens: Simatic S7 1500 Cpu 1518 4 Pn/dp Mfp Firmware, Simatic S7 1500 Cpu 1518f 4 Pn/dp Mfp Firmware, Siplus S7 1500 Cpu 1518 4 Pn/dp Mfp Firmware, Simatic S7 1500 Tm Mfp Firmware · Gnu: Glibc · +4 more
Show all products
Netapp: Bootstrap Os, H410c Firmware, H300s Firmware, H500s Firmware, H700s Firmware, H410s Firmware, Ontap Select Deploy Administration Utility · Siemens: Simatic S7 1500 Cpu 1518 4 Pn/dp Mfp Firmware, Simatic S7 1500 Cpu 1518f 4 Pn/dp Mfp Firmware, Siplus S7 1500 Cpu 1518 4 Pn/dp Mfp Firmware, Simatic S7 1500 Tm Mfp Firmware · Gnu: Glibc · Fedoraproject: Fedora · Redhat: Codeready Linux Builder, Codeready Linux Builder Eus, Codeready Linux Builder For Arm64, Codeready Linux Builder For Arm64 Eus, Codeready Linux Builder For Ibm Z Systems, Codeready Linux Builder For Ibm Z Systems Eus, Codeready Linux Builder For Power Little Endian, Codeready Linux Builder For Power Little Endian Eus, Enterprise Linux, Enterprise Linux Eus, Enterprise Linux For Arm 64, Enterprise Linux For Arm 64 Eus, Enterprise Linux For Ibm Z Systems, Enterprise Linux For Ibm Z Systems Eus, Enterprise Linux For Ibm Z Systems Eus S390x, Enterprise Linux For Power Big Endian Eus, Enterprise Linux For Power Little Endian, Enterprise Linux For Power Little Endian Eus, Enterprise Linux Server Aus, Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions, Enterprise Linux Server Tus, Enterprise Linux Update Services For Sap Solutions, Virtualization, Virtualization Host · Canonical: Ubuntu Linux · Debian: Debian Linux
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp Hci Compute Node | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.1.5 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 1500 Cpu 1518 4 Pn/dp Mfp | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.1.5 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 1500 Cpu 1518f 4 Pn/dp Mfp | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.1.5 |
| Running on/with | Platform Versions |
|---|---|
Siemens Siplus S7 1500 Cpu 1518 4 Pn/dp Mfp | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.1 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 1500 Tm Mfp | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 37 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.0 | |
| Version 8.6 | |
| Version 9.0_aarch64 | |
| Version 8.6 | |
| Version 9.0_s390x | |
| Version 8.6 | |
| Version 9.0_ppc64le | |
| Version 8.6 | |
| Version 8.0 | |
| Version 8.6 | |
| Version 9.0_aarch64 | |
| Version 8.6_aarch64 | |
| Version 9.0_s390x | |
| Version 9.2_s390x | |
| Version 8.6 | |
| Version 8.6_ppc64le | |
| Version 9.0_ppc64le | |
| Version 9.2_ppc64le | |
| Version 8.6 | |
| Version 9.2_ppc64le | |
| Version 8.6 | |
| Version 9.2 | |
| Version 4.0 | |
| Version 4.0 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 22.04 | |
| Version 11.0 |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H410c | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H300s | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H500s | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H700s | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H410s | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
Related CWEs
CWE-122
Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
CWE-787
Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
References (39)
Source: secalert@redhat.com
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
Third Party Advisory
Source: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
Third Party Advisory
Source: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
Third Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource
Timeline
No history available yet.