First published: Wed Mar 02 2011(Updated: )
Common Vulnerabilities and Exposures assigned an identifier <a href="https://access.redhat.com/security/cve/CVE-2010-4756">CVE-2010-4756</a> to the following vulnerability: Name: <a href="https://access.redhat.com/security/cve/CVE-2010-4756">CVE-2010-4756</a> URL: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4756">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4756</a> Assigned: 20110302 Reference: <a href="http://securityreason.com/achievement_securityalert/89">http://securityreason.com/achievement_securityalert/89</a> Reference: <a href="http://cxib.net/stuff/glob-0day.c">http://cxib.net/stuff/glob-0day.c</a> Reference: <a href="http://securityreason.com/exploitalert/9223">http://securityreason.com/exploitalert/9223</a> The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than <a href="https://access.redhat.com/security/cve/CVE-2010-2632">CVE-2010-2632</a>.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Analytics | <=12.0.0-12.0.2 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP3 | |
GNU C Library | ||
GNU C Library (glibc) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-4756 is classified as a medium severity vulnerability.
To fix CVE-2010-4756, apply the latest security patches provided by IBM for Cognos Analytics.
CVE-2010-4756 affects IBM Cognos Analytics versions up to and including 12.0.2 and 11.2.4 FP3.
Yes, CVE-2010-4756 also affects various versions of the GNU C Library (glibc).
CVE-2010-4756 is a remote code execution vulnerability that may lead to unauthorized access.