9.8
CVSSv3

CVE-2019-14697

Published: 06/08/2019 Updated: 03/03/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

musl libc up to and including 1.1.23 has an x87 floating-point stack adjustment imbalance, related to the math/i386/ directory. In some cases, use of this library could introduce out-of-bounds writes that are not present in an application's source code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

musl-libc musl

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Re: [musl] CVE request: musl libc 1123 and earlier x87 float stack imbalance <!--X-Subject-Header-End--> <!--X-Head-of-Messa ...

Github Repositories

A largely compatible node 10 alpine base image

docker-node10 A largely compatible node 10 alpine base image baked to respond to vulnerabilities As node-alpine is still using alpine 39 - the base image is vulnerable - CVE-2019-14697 This is fixed in alpine 310/latest and as there are other vulnerabilities coming to light so we will aim to keep this image up to date as they pop up As I am planning to switch to node 12 soo

A largely compatible node 12 alpine base image baked to respond to vulnerabilities

docker-node12 A largely compatible node 12 alpine base image baked to respond to vulnerabilities As node-alpine is still using alpine 39 - the base image is vulnerable - CVE-2019-14697 This is fixed in alpine 310/latest and as there are other vulnerabilities coming to light so we will aim to keep this image up to date as they pop up This is a patched image based on alpine 3

A "mini demo" of image governance using Tanzu Mission Control and the Harbor registry.

Image Governance with Harbor and Tanzu Mission Control This repository contains the code and configuration needed to demonstrate container image governance with Tanzu Mission Control and Harbor Scenario The demonstration considers a context in which a team is has a development process that builds, tests, and deploys software using multiple environments Each environment has di

Jenkins pipeline shared library adding features for Maven, Gradle, Docker, SonarQube, Git and others

ces-build-lib Jenkins Pipeline Shared library, that contains additional features for Git, Maven, etc in an object-oriented manner as well as some additional pipeline steps Table of contents Usage Syntax completion Maven Maven from local Jenkins tool Maven Wrapper With local JDK tool With the JDK provided by the build agent Maven in Docker Plain Maven In Docker Maven