Executive Summary

Informations
NameCVE-2010-0830First vendor Publication2010-06-01
VendorCveLast vendor Modification2011-01-12

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:H/Au:N/C:P/I:P/A:P)
Cvss Base Score5.1Attack RangeNetwork
Cvss Impact Score6.4Attack ComplexityHigh
Cvss Expoit Score4.9AuthentificationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

Integer signedness error in the elf_get_dynamic_info function in elf/dynamic-link.h in ld.so in the GNU C Library (aka glibc or libc6) 2.0.1 through 2.11.1, when the --verify option is used, allows user-assisted remote attackers to execute arbitrary code via a crafted ELF program with a negative value for a certain d_tag structure member in the ELF header.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0830

CWE : Common Weakness Enumeration

idName
CWE-189Numeric Errors

CPE : Common Platform Enumeration

TypeDescriptionCount
Application38

Open Source Vulnerability Database (OSVDB)

idDescription
65077GNU C Library ld.so elf/dynamic-link.h elf_get_dynamic_info Crafted ELF Progr...

Internal Sources (Detail)

SourceUrl
BIDhttp://www.securityfocus.com/bid/40063
CONFIRMhttp://frugalware.org/security/662
http://sourceware.org/git/?p=glibc.git;a=commit;h=db07e962b6ea963dbb345439f6a...
DEBIANhttp://www.debian.org/security/2010/dsa-2058
GENTOOhttp://security.gentoo.org/glsa/glsa-201011-01.xml
MANDRIVAhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:111
http://www.mandriva.com/security/advisories?name=MDVSA-2010:112
MISChttp://drosenbe.blogspot.com/2010/05/integer-overflow-in-ldso-cve-2010-0830.html
SECTRACKhttp://securitytracker.com/id?1024044
SECUNIAhttp://secunia.com/advisories/39900
UBUNTUhttp://www.ubuntu.com/usn/USN-944-1
VUPENhttp://www.vupen.com/english/advisories/2010/1246
XFhttp://xforce.iss.net/xforce/xfdb/58915

Alert History

If you want to see full details history, please login or register.
0
DateInformations
2013-05-10 23:19:38
  • Multiple Updates