Stack-based buffer overflow in the glibtop_get_proc_map_s function in libgtop before 2.14.6 (libgtop2) allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a process with a long filename that is mapped in its address space, which triggers the overflow in gnome-system-monitor.
CVSS Details
- CVSS 3.1 Base Score: 8.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libgtop2 | Jul 30, 2024 | Jan 16, 2007 |
| Gentoo Linux | — | Upgrade gnome-base/libgtop. | Oct 30, 2017 | Jan 16, 2007 |
| Suse | — | Upgrade libgtopUpgrade libgtop-2_0-7Upgrade libgtop-2_0-7-32bitUpgrade libgtop-2_0-11Upgrade typelib-1_0-GTop-2_0Upgrade libgtop-develUpgrade libgtop-langUpgrade libgtop-docUpgrade libgtop-2_0-7-x86 | Dec 12, 2013 | Jun 27, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub