Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The posix_spawn_file_actions_addopen function in glibc before 2.20 does not copy its path argument in accordance with the POSIX specification, which allows context-dependent attackers to trigger use-after-free vulnerabilities.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
glibc‘posix_spawn_file_actions_addopen()’代码注入漏洞
Vulnerability Description
glibc(又名GNU C Library,libc6)是一种按照LGPL许可协议发布的开源免费的C语言编译程序。 glibc 2.19及之前版本中的‘posix_spawn_file_actions_addopen’函数中存在安全漏洞,该漏洞源于程序没有正确复制‘path’参数。攻击者可利用该漏洞执行任意代码或造成拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A