UBUNTU-CVE-2022-23218
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-23218
UBUNTU-CVE-2022-23218
Summary:
Details: The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.
References: https://ubuntu.com/security/CVE-2022-23218, https://ubuntu.com/security/notices/USN-5310-1, https://ubuntu.com/security/notices/USN-5310-2, https://www.cve.org/CVERecord?id=CVE-2022-23218
Affected packages
Package
Name: eglibc
Purl: pkg:deb/ubuntu/[email protected]+esm4?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
