Lucene search

K
archlinuxArch LinuxASA-201605-19
HistoryMay 13, 2016 - 12:00 a.m.

glibc: multiple issues

2016-05-1300:00:00
Arch Linux
lists.archlinux.org
17

0.013 Low

EPSS

Percentile

86.1%

  • CVE-2016-1234 (arbitrary code execution)

It was found that glob implementation in glibc does not correctly
handle overlong names in struct dirent buffers when GLOB_ALTDIRFUNC is
used, causing a large stack-based buffer overflow with controlled
length and content.

  • CVE-2016-3706 (denial of service)

A stack (frame) overflow flaw, which could lead to a denial of service
(application crash), was found in the way glibc’s getaddrinfo()
function processed certain requests when called with AF_INET or
AF_INET6.

OSVersionArchitecturePackageVersionFilename
anyanyanyglibc< 2.23-4UNKNOWN