安全公告/【CVE-2021-3999】
基本信息
受影响操作系统:Asianux
危险等级:高危
影响源码包:glibc
CVSS评分:7.8
发现日期:2022-09-28
修复版本:2.28-189.1.0.1.01
漏洞描述
A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the buffer is exactly 1. A local attacker who can control the input buffer and size passed to getcwd() in a setuid program could use this flaw to potentially execute arbitrary code and escalate their privileges on the system.
漏洞判定
执行命令yum info PackageName获取软件包版本号,版本小于修复版本,则受此漏洞影响,版本大于等于修复版本,则此漏洞已修复
修复方式
yum update PackageName