Vulnerabilidades en GNU Libc
4 resultadosAnálisis Vexday
A GNU Libc apresenta 4 vulnerabilidades catalogadas, nenhuma delas em exploração ativa ou com severidade crítica, indicando um nível de risco contido. A fraqueza dominante é CWE-416 (use-after-free), padrão em bibliotecas de sistema, sem publicações recentes que sinalizem evolução aguda do cenário de risco.
CVE-2019-1010024—GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The componEPSS 3.2%CVE-2019-1010023MEDIUMGNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluaEPSS 3.0%CVE-2019-1010025—GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The compEPSS 2.3%CVE-2020-1752HIGHA use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. DirectoryEPSS 0.5%