在 GNU C 库(版本 2.38 到 2.44)中,调用 和 时,当转换使用了右对齐的宽度填充时,可能会写入超出调用者提供的输出缓冲区的末尾。 利用该漏洞需要应用代码路径满足以下条件:调用 或 并使用了右对齐的宽度填充,目标缓冲区对于填充操作足够大,但对于内部的 调用又太小。字段宽度或格式可以由攻击者影响,或为调用方中固定的易受影响的模式。 在公告发布时,尚不知晓该漏洞对面向网络的应用程序有何影响。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| The GNU C Library | glibc | 2.38≤ 2.44 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| The GNU C Library | glibc | 2.38 ~ 2.44 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet