First published: Tue Oct 06 2020(Updated: )
manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion of a tree's root, which might allow attackers to access a dangling pointer in an application whose developer was unaware of a documentation update from 1999.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU C Library (glibc) | <2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-1999-0199.
CVE-1999-0199 has a severity rating of 9.8 (Critical).
Attackers can exploit CVE-1999-0199 to access a dangling pointer in an application whose developer was unaware of a documentation update from 1999.
GNU glibc versions before 2.2 are affected by CVE-1999-0199.
Yes, you can find more information about CVE-1999-0199 in the following references: [1](https://ftp.gnu.org/gnu/glibc/glibc-2.2.tar.gz), [2](https://www.cee.studio/tdelete.html), [3](https://github.com/bminor/glibc/commit/2864e767053317538feafa815046fff89e5a16be#diff-94e8c502f255fdfc346df0e29fd4ef40)