7.2
CVSSv2

CVE-2007-3508

Published: 03/07/2007 Updated: 11/04/2024
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Integer overflow in the process_envvars function in elf/rtld.c in glibc prior to 2.5-rc4 might allow local users to execute arbitrary code via a large LD_HWCAP_MASK environment variable value. NOTE: the glibc maintainers state that they do not believe that this issue is exploitable for code execution

Vulnerable Product Search on Vulmon Subscribe to Product

gentoo glibc

Vendor Advisories

Debian Bug report logs - #431858 CVE-2007-3508: Integer overflow Package: libc6; Maintainer for libc6 is GNU Libc Maintainers <debian-glibc@listsdebianorg>; Source for libc6 is src:glibc (PTS, buildd, popcon) Reported by: Laurent Bonnaud <LaurentBonnaud@inpgfr> Date: Thu, 5 Jul 2007 13:57:02 UTC Severity: impor ...