vulnerability

Oracle Linux: CVE-2018-11236: ELSA-2018-3092: glibc security, bug fix, and enhancement update (MODERATE)

Severity
7
CVSS
(AV:L/AC:L/Au:S/C:C/I:C/A:C)
Published
Feb 4, 2018
Added
Nov 6, 2018
Modified
Nov 27, 2024

Description

stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures, leading to a stack-based buffer overflow and, potentially, arbitrary code execution.

Solution(s)

oracle-linux-upgrade-glibcoracle-linux-upgrade-glibc-commonoracle-linux-upgrade-glibc-develoracle-linux-upgrade-glibc-headersoracle-linux-upgrade-glibc-staticoracle-linux-upgrade-glibc-utilsoracle-linux-upgrade-nscd
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.