Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:19187
HistoryMay 16, 2019 - 2:50 a.m.

Arbitrary Code Execution

2019-05-1602:50:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.005 Low

EPSS

Percentile

77.0%

glibc is vulnerable to arbitrary code execution. A local authenticated attacker could write before the destination buffer leading to a buffer underflow and potential code execution due to a confusion in the usage of getcwd() by realpath(). Affected is the function __realpath in the library stdlib/canonicalize.c.

References