CVE-2010-0830: Medium severity GNU glibc vulnerability
Integer signedness error in the elfgetdynamicinfo function in elf/dynamic-link.h in ld.so in the GNU C Library (aka glibc or libc6) 2.0.1 through 2.11.1, when the --verify option is used, allows user-assisted remote attackers to execute arbitrary code via a crafted ELF program with a negative value for a certain dtag structure member in the ELF header.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0830?
CVE-2010-0830 is considered a medium severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2010-0830?
To fix CVE-2010-0830, update the GNU C Library to version 2.11.2 or later.
What systems are affected by CVE-2010-0830?
CVE-2010-0830 affects GNU C Library versions from 2.0.1 to 2.11.1.
What kind of attack does CVE-2010-0830 enable?
CVE-2010-0830 enables user-assisted remote attackers to execute arbitrary code.
What component of the system does CVE-2010-0830 impact?
CVE-2010-0830 impacts the elf_get_dynamic_info function in the dynamic linker of the GNU C Library.