This is the mail archive of the glibc-bugs@sourceware.org mailing list for the glibc project.


Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]
Other format: [Raw text]

[Bug libc/18012] New: Alleged denial of service in glob (CVE-2010-4756)


https://sourceware.org/bugzilla/show_bug.cgi?id=18012

            Bug ID: 18012
           Summary: Alleged denial of service in glob (CVE-2010-4756)
           Product: glibc
           Version: unspecified
            Status: NEW
          Severity: normal
          Priority: P2
         Component: libc
          Assignee: unassigned at sourceware dot org
          Reporter: fweimer at redhat dot com
                CC: drepper.fsp at gmail dot com

Common Vulnerabilities and Exposures assigned an identifier CVE-2010-4756 to
the following vulnerability:

Name: CVE-2010-4756
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4756
Assigned: 20110302
Reference: http://securityreason.com/achievement_securityalert/89
Reference: http://cxib.net/stuff/glob-0day.c
Reference: http://securityreason.com/exploitalert/9223

The glob implementation in the GNU C Library (aka glibc or libc6) allows remote
authenticated users to cause a denial of service (CPU and memory consumption)
via crafted glob expressions that do not match any pathnames, as demonstrated
by glob expressions in STAT commands to an FTP daemon, a different
vulnerability than CVE-2010-2632.

-- 
You are receiving this mail because:
You are on the CC list for the bug.


Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]