UBUNTU-CVE-2021-3999
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-3999
UBUNTU-CVE-2021-3999
Summary:
Details: A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the buffer is exactly 1. A local attacker who can control the input buffer and size passed to getcwd() in a setuid program could use this flaw to potentially execute arbitrary code and escalate their privileges on the system.
References: https://ubuntu.com/security/CVE-2021-3999, https://ubuntu.com/security/notices/USN-5310-1, https://ubuntu.com/security/notices/USN-5310-2, https://www.cve.org/CVERecord?id=CVE-2021-3999, https://ubuntu.com/security/notices/USN-6762-1
Affected packages
Package
Name: eglibc
Purl: pkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
