First published: Tue Jul 03 2007(Updated: )
** DISPUTED ** Integer overflow in the process_envvars function in elf/rtld.c in glibc before 2.5-rc4 might allow local users to execute arbitrary code via a large LD_HWCAP_MASK environment variable value. NOTE: the glibc maintainers state that they do not believe that this issue is exploitable for code execution.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gentoo Glibc | <=2.5 | |
<=2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3508 is disputed and not widely considered to be exploitable, but it involves an integer overflow vulnerability.
To mitigate CVE-2007-3508, upgrade to glibc version 2.5 or later.
CVE-2007-3508 impacts glibc versions before 2.5-rc4, specifically on Gentoo systems.
CVE-2007-3508 was reported by the community and its validity was later disputed by glibc maintainers.
CVE-2007-3508 could potentially allow local users to execute arbitrary code under certain conditions.