CVE-2014-9761: Buffer Overflow
A stack overflow vulnerability was found in nan functions that could cause applications which process long strings with the nan function to crash or, potentially, execute arbitrary code.
Upstream bug:
https://sourceware.org/bugzilla/showbug.cgi?id=16962
CVE assignment:
http://seclists.org/oss-sec/2016/q1/153
Other sources
Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long argument to the (1) nan, (2) nanf, or (3) nanl function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9761?
CVE-2014-9761 is a critical vulnerability that can lead to application crashes and potentially allow execution of arbitrary code.
How do I fix CVE-2014-9761?
To fix CVE-2014-9761, update the affected glibc packages to versions later than 2.23.
Which software is affected by CVE-2014-9761?
CVE-2014-9761 affects versions of glibc up to 2.22 and specific versions of SUSE Linux and Ubuntu.
What types of attacks can exploit CVE-2014-9761?
Exploitation of CVE-2014-9761 can lead to remote code execution and denial of service attacks.
Is CVE-2014-9761 already patched?
Yes, CVE-2014-9761 has been patched in glibc versions 2.23 and later.