Multiple integer overflows in the (1) GC_generic_malloc and (2) calloc functions in malloc.c, and the (3) GC_generic_malloc_ignore_off_page function in mallocx.c in Boehm-Demers-Weiser GC (libgc) before 7.2 make it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large size value, which causes less memory to be allocated than expected.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade gcUpgrade gc-devel | Dec 1, 2016 | Jul 25, 2012 |
| Debian | — | Upgrade libgc | Jul 30, 2024 | Jul 25, 2012 |
| Oracle_linux | — | Upgrade gcUpgrade gc-devel | Oct 16, 2024 | Jul 25, 2012 |
| Suse | — | Upgrade gc-develUpgrade libgc1 | Aug 9, 2024 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libgc1c2 | Nov 8, 2024 | Jul 25, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub