Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Integer overflow in the __tzfile_read function in glibc before 2.15 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted timezone (TZ) file, as demonstrated using vsftpd.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
GNU C Library 数字错误漏洞
Vulnerability Description
GNU C Library(glibc,libc6)是一种按照LGPL许可协议发布的开源免费的C语言编译程序。 glibc 2.15之前的版本中的‘__tzfile_read’函数中存在数字错误漏洞。上下文相关的攻击者可通过特制的时区(TZ)文件(如使用vsftpd)利用该漏洞造成拒绝服务(崩溃),也可能执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A