Vulnerability Description
The GNU C Library (aka glibc or libc6) before 2.12.2 and Embedded GLIBC (EGLIBC) allow context-dependent attackers to execute arbitrary code or cause a denial of service (memory consumption) via a long UTF8 string that is used in an fnmatch call, aka a "stack extension attack," a related issue to CVE-2010-2898, CVE-2010-1917, and CVE-2007-4782, as originally reported for use of this library by Google Chrome.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Eglibc | All versions |
| Gnu | Glibc | <= 2.12.1 |
Related Weaknesses (CWE)
References
- http://bugs.debian.org/615120Exploit
- http://code.google.com/p/chromium/issues/detail?id=48733Exploit
- http://openwall.com/lists/oss-security/2011/02/26/3
- http://openwall.com/lists/oss-security/2011/02/28/11Exploit
- http://openwall.com/lists/oss-security/2011/02/28/15
- http://scarybeastsecurity.blogspot.com/2011/02/i-got-accidental-code-execution-vExploit
- http://seclists.org/fulldisclosure/2011/Feb/635Exploit
- http://seclists.org/fulldisclosure/2011/Feb/644Patch
- http://secunia.com/advisories/43492Vendor Advisory
- http://secunia.com/advisories/43830Vendor Advisory
- http://secunia.com/advisories/43989Vendor Advisory
- http://secunia.com/advisories/46397Vendor Advisory
- http://securityreason.com/securityalert/8175
- http://securitytracker.com/id?1025290
- http://sourceware.org/bugzilla/show_bug.cgi?id=11883Exploit
FAQ
What is CVE-2011-1071?
CVE-2011-1071 is a vulnerability with a CVSS score of 5.1 (MEDIUM). The GNU C Library (aka glibc or libc6) before 2.12.2 and Embedded GLIBC (EGLIBC) allow context-dependent attackers to execute arbitrary code or cause a denial of service (memory consumption) via a lon...
How severe is CVE-2011-1071?
CVE-2011-1071 has been rated MEDIUM with a CVSS base score of 5.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-1071?
Check the references section above for vendor advisories and patch information. Affected products include: Gnu Eglibc, Gnu Glibc.