Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:19533
HistoryMay 16, 2019 - 3:18 a.m.

Arbitrary Code Execution

2019-05-1603:18:40
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15

0.014 Low

EPSS

Percentile

86.6%

GNU C Library is vulnerable to arbitrary code execution attacks. This occurs in the stdlib/canonicalize.c when processing very long pathname arguments to the realpath function which may encounter an integer overflow on 32-bit architectures, leading to a stack-based buffer overflow and potentially arbitrary code execution.

References