CVE-2007-3508: Integer Overflow
DISPUTED Integer overflow in the processenvvars function in elf/rtld.c in glibc before 2.5-rc4 might allow local users to execute arbitrary code via a large LDHWCAPMASK environment variable value. NOTE: the glibc maintainers state that they do not believe that this issue is exploitable for code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3508?
CVE-2007-3508 is disputed and not widely considered to be exploitable, but it involves an integer overflow vulnerability.
How do I fix CVE-2007-3508?
To mitigate CVE-2007-3508, upgrade to glibc version 2.5 or later.
Which systems are affected by CVE-2007-3508?
CVE-2007-3508 impacts glibc versions before 2.5-rc4, specifically on Gentoo systems.
Who reported CVE-2007-3508?
CVE-2007-3508 was reported by the community and its validity was later disputed by glibc maintainers.
What are the potential consequences of CVE-2007-3508?
CVE-2007-3508 could potentially allow local users to execute arbitrary code under certain conditions.