First published: Wed Apr 10 2019(Updated: )
The getgrouplist function in the GNU C library (glibc) before version 2.3.5, when invoked with a zero argument, writes to the passed pointer even if the specified array size is zero, leading to a buffer overflow and potentially allowing attackers to corrupt memory.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU glibc | <2.3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this security issue is CVE-2005-3590.
The title of this vulnerability is 'The getgrouplist function in the GNU C library (glibc) before version 2.3.5'.
The severity of CVE-2005-3590 is critical with a severity value of 9.8.
CVE-2005-3590 affects the GNU C library (glibc) before version 2.3.5.
To fix CVE-2005-3590, update the GNU C library (glibc) to version 2.3.5 or later.