UBUNTU-CVE-2020-6096
Dashboard / Vulnerabilities / UBUNTU-CVE-2020-6096
UBUNTU-CVE-2020-6096
Summary:
Details: An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) with a negative value for the 'num' parameter results in a signed comparison vulnerability. If an attacker underflows the 'num' parameter to memcpy(), this vulnerability could lead to undefined behavior such as writing to out-of-bounds memory and potentially remote code execution. Furthermore, this memcpy() implementation allows for program execution to continue in scenarios where a segmentation fault or crash should have occurred. The dangers occur in that subsequent execution and iterations of this code will be executed with this corrupted data.
References: https://ubuntu.com/security/CVE-2020-6096, https://talosintelligence.com/vulnerability_reports/TALOS-2020-1019, https://ubuntu.com/security/notices/USN-4954-1, https://ubuntu.com/security/notices/USN-5310-1, https://www.cve.org/CVERecord?id=CVE-2020-6096
Affected packages
Package
Name: eglibc
Purl: pkg:deb/ubuntu/[email protected]+esm4?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
