CVE-2012-1568: Low severity Fedoraproject Fedora vulnerability
The ExecShield feature in a certain Red Hat patch for the Linux kernel in Red Hat Enterprise Linux (RHEL) 5 and 6 and Fedora 15 and 16 does not properly handle use of many shared libraries by a 32-bit executable file, which makes it easier for context-dependent attackers to bypass the ASLR protection mechanism by leveraging a predictable base address for one of these libraries.
Other sources
When running a binary with a lot of shared libraries, predictable base address is used for one of the loaded libraries.
This flaw could be used to bypass ASLR.
References: http://scarybeastsecurity.blogspot.com/2012/03/some-random-observations-on-linux-aslr.html
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1568?
CVE-2012-1568 is classified as a moderate severity vulnerability.
How do I fix CVE-2012-1568?
To fix CVE-2012-1568, update your system with the latest patches provided by Red Hat or Fedora.
What systems are affected by CVE-2012-1568?
CVE-2012-1568 affects Red Hat Enterprise Linux versions 5 and 6, as well as Fedora versions 15 and 16.
What impact does CVE-2012-1568 have on system security?
CVE-2012-1568 may allow attackers to bypass Address Space Layout Randomization (ASLR) protections.
Is there a known exploit for CVE-2012-1568?
While there are no publicly known exploits specifically for CVE-2012-1568, the vulnerability can potentially be leveraged by attackers.