The GNU C Library (aka glibc or libc6) before 2.12.2 and Embedded GLIBC (EGLIBC) allow context-dependent attackers to execute arbitrary code or cause a denial of service (memory consumption) via a long UTF8 string that is used in an fnmatch call, aka a "stack extension attack," a related issue to CVE-2010-2898, CVE-2010-1917, and CVE-2007-4782, as originally reported for use of this library by Google Chrome.
http://code.google.com/p/chromium/issues/detail?id=48733
http://openwall.com/lists/oss-security/2011/02/26/3
http://openwall.com/lists/oss-security/2011/02/28/11
http://openwall.com/lists/oss-security/2011/02/28/15
http://scarybeastsecurity.blogspot.com/2011/02/i-got-accidental-code-execution-via.html
http://seclists.org/fulldisclosure/2011/Feb/635
http://seclists.org/fulldisclosure/2011/Feb/644
http://secunia.com/advisories/43492
http://secunia.com/advisories/43830
http://secunia.com/advisories/43989
http://secunia.com/advisories/46397
http://securityreason.com/securityalert/8175
http://securitytracker.com/id?1025290
http://sourceware.org/bugzilla/show_bug.cgi?id=11883
http://sourceware.org/git/?p=glibc.git;a=commit;h=f15ce4d8dc139523fe0c273580b604b2453acba6
http://www.mandriva.com/security/advisories?name=MDVSA-2011:178
http://www.redhat.com/support/errata/RHSA-2011-0412.html
http://www.redhat.com/support/errata/RHSA-2011-0413.html
http://www.securityfocus.com/archive/1/520102/100/0/threaded
http://www.securityfocus.com/bid/46563
http://www.vmware.com/security/advisories/VMSA-2011-0012.html
http://www.vupen.com/english/advisories/2011/0863
https://bugzilla.redhat.com/show_bug.cgi?id=681054
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12853
OR
cpe:2.3:a:gnu:eglibc:*:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:1.00:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:1.01:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:1.02:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:1.03:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:1.04:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:1.05:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:1.06:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:1.07:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:1.08:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:1.09:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:1.09.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.0:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.0.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.0.4:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.0.5:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.0.6:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.1.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.1.1.6:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.1.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.1.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.1.3.10:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.1.9:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.2.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.2.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.2.4:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.2.5:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.3.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.3.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.3.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.3.4:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.3.5:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.3.6:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.3.10:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.4:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.5:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.5.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.6:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.6.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.7:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.8:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.9:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.10:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.10.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.10.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.11:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.11.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.11.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.11.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:2.12.0:*:*:*:*:*:*:*
cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:* versions up to 2.12.1 (inclusive)
ID | Name | Product | Family | Severity |
---|---|---|---|---|
93030 | F5 Networks BIG-IP : glibc vulnerability (SOL09408132) | Nessus | F5 Networks Local Security Checks | medium |
89680 | VMware ESX / ESXi Third-Party Libraries Multiple Vulnerabilities (VMSA-2011-0012) (remote check) | Nessus | Misc. | high |
89679 | VMware ESX Third-Party Libraries Multiple Vulnerabilities (VMSA-2011-0010) (remote check) | Nessus | Misc. | high |
81118 | OracleVM 3.2 : glibc (OVMSA-2015-0023) (GHOST) | Nessus | OracleVM Local Security Checks | high |
79606 | F5 Networks BIG-IP : GNU C Library vulnerability (SOL15885) | Nessus | F5 Networks Local Security Checks | critical |
71167 | GLSA-201312-01 : GNU C Library: Multiple vulnerabilities | Nessus | Gentoo Local Security Checks | medium |
70880 | ESXi 5.0 < Build 515841 Multiple Vulnerabilities (remote check) | Nessus | Misc. | high |
68455 | Oracle Linux 4 : glibc (ELSA-2012-0125) | Nessus | Oracle Linux Local Security Checks | high |
68245 | Oracle Linux 6 : glibc (ELSA-2011-0413) | Nessus | Oracle Linux Local Security Checks | medium |
68244 | Oracle Linux 5 : glibc (ELSA-2011-0412) | Nessus | Oracle Linux Local Security Checks | high |
61243 | Scientific Linux Security Update : glibc on SL4.x i386/x86_64 (20120213) | Nessus | Scientific Linux Local Security Checks | high |
61008 | Scientific Linux Security Update : glibc on SL5.x,SL6.x i386/x86_64 | Nessus | Scientific Linux Local Security Checks | medium |
58318 | Ubuntu 8.04 LTS / 10.04 LTS / 10.10 / 11.04 / 11.10 : eglibc, glibc vulnerabilities (USN-1396-1) | Nessus | Ubuntu Local Security Checks | high |
57928 | RHEL 4 : glibc (RHSA-2012:0125) | Nessus | Red Hat Local Security Checks | high |
57923 | CentOS 4 : glibc (CESA-2012:0125) | Nessus | CentOS Local Security Checks | high |
57201 | SuSE 10 Security Update : glibc (ZYPP Patch Number 7574) | Nessus | SuSE Local Security Checks | medium |
57106 | SuSE 11.1 Security Update : glibc (SAT Patch Number 4572) | Nessus | SuSE Local Security Checks | high |
56953 | Mandriva Linux Security Advisory : glibc (MDVSA-2011:178) | Nessus | Mandriva Local Security Checks | medium |
56508 | VMSA-2011-0012 : VMware ESXi and ESX updates to third-party libraries and ESX Service Console | Nessus | VMware ESX Local Security Checks | high |
55747 | VMSA-2011-0010 : VMware ESX third-party updates for Service Console packages glibc and dhcp | Nessus | VMware ESX Local Security Checks | high |
55442 | SuSE 10 Security Update : glibc (ZYPP Patch Number 7575) | Nessus | SuSE Local Security Checks | medium |
55441 | SuSE 11.1 Security Update : glibc (SAT Patch Number 4572) | Nessus | SuSE Local Security Checks | high |
55440 | SuSE9 Security Update : glibc (YOU Patch Number 12775) | Nessus | SuSE Local Security Checks | medium |
53430 | CentOS 5 : glibc (CESA-2011:0412) | Nessus | CentOS Local Security Checks | high |
53292 | RHEL 6 : glibc (RHSA-2011:0413) | Nessus | Red Hat Local Security Checks | medium |
53291 | RHEL 5 : glibc (RHSA-2011:0412) | Nessus | Red Hat Local Security Checks | high |