安全公告/【CVE-2021-3999】

基本信息

漏洞名称:
受影响操作系统:Asianux
危险等级:高危
影响源码包:glibc
CVSS评分:7.8
发现日期:2022-09-28
修复日期:
修复版本:2.28-189.1.0.1.01

漏洞描述

A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the buffer is exactly 1. A local attacker who can control the input buffer and size passed to getcwd() in a setuid program could use this flaw to potentially execute arbitrary code and escalate their privileges on the system.

漏洞判定

执行命令yum info PackageName获取软件包版本号,版本小于修复版本,则受此漏洞影响,版本大于等于修复版本,则此漏洞已修复

修复方式

yum update PackageName

补丁