Lucene search

K
f5F5F5:K15885
HistoryJun 13, 2015 - 12:00 a.m.

K15885 : GNU C Library vulnerability CVE-2011-1071

2015-06-1300:00:00
my.f5.com
19

AI Score

8

Confidence

Low

EPSS

0.022

Percentile

89.6%

Security Advisory Description

The GNU C Library (aka glibc or libc6) before 2.12.2 and Embedded GLIBC (EGLIBC) allow context-dependent attackers to execute arbitrary code or cause a denial of service (memory consumption) via a long UTF8 string that is used in an fnmatch call, aka a “stack extension attack,” a related issue to CVE-2010-2898, CVE-2010-1917, and CVE-2007-4782, as originally reported for use of this library by Google Chrome. (CVE-2011-1071)

Impact

An attacker may be able to run arbitrary code or cause a denial of service (memory consumption) by way of a long UTF8 string.