7.2
CVSSv2

CVE-2017-1000408

Published: 01/02/2018 Updated: 03/10/2019
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu glibc 2.1.1

Vendor Advisories

Debian Bug report logs - #884132 glibc: CVE-2017-1000408 Package: src:glibc; Maintainer for src:glibc is GNU Libc Maintainers <debian-glibc@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 11 Dec 2017 19:39:01 UTC Severity: important Tags: security, upstream Found in version glibc/ ...
Debian Bug report logs - #884133 glibc: CVE-2017-1000409 Package: src:glibc; Maintainer for src:glibc is GNU Libc Maintainers <debian-glibc@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 11 Dec 2017 19:39:04 UTC Severity: important Tags: security, upstream Found in version glibc/ ...
Several security issues were fixed in the GNU C library ...
A memory leak in glibc 211 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environment variable Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366 ...

Exploits

Qualys Security Advisory Buffer overflow in glibc's ldso ======================================================================== Contents ======================================================================== Summary Memory Leak Buffer Overflow Exploitation Acknowledgments ================================================================== ...
Qualys has discovered a memory leak and a buffer overflow in the dynamic loader (ldso) of the GNU C Library (glibc) ...