Lucene search

K
osvGoogleOSV:USN-4954-1
HistoryMay 14, 2021 - 12:19 a.m.

glibc vulnerabilities

2021-05-1400:19:34
Google
osv.dev
10
glibc
gnu c library
memcpy
integer underflow
arm processors
denial of service
arbitrary code
posix regex
cve-2020-6096
cve-2009-5155

AI Score

6.6

Confidence

High

EPSS

0.074

Percentile

94.1%

Jason Royes and Samuel Dytrych discovered that the memcpy()
implementation for 32 bit ARM processors in the GNU C Library contained
an integer underflow vulnerability. An attacker could possibly use
this to cause a denial of service (application crash) or execute
arbitrary code. (CVE-2020-6096)

It was discovered that the POSIX regex implementation in the GNU C
Library did not properly parse alternatives. An attacker could use this
to cause a denial of service. (CVE-2009-5155)