First published: Wed Mar 04 2020(Updated: )
GNU C Library (aka glibc or libc6) is vulnerable to a denial of service, caused by a stack-based overflow during range reduction. A local attacker could exploit this vulnerability to cause a stack corruption, leading to a denial of service condition.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU glibc | <2.32.0 | |
Fedoraproject Fedora | =30 | |
Fedoraproject Fedora | =31 | |
Fedoraproject Fedora | =32 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =19.10 | |
openSUSE Leap | =15.1 | |
Netapp Active Iq Unified Manager Vmware Vsphere | ||
Netapp Cloud Backup | ||
Netapp Hci Management Node | ||
Netapp Solidfire | ||
Netapp Steelstore Cloud Integrated Storage | ||
All of | ||
Netapp H410c Firmware | ||
Netapp H410c | ||
Debian Debian Linux | =10.0 | |
Netapp H410c Firmware | ||
Netapp H410c | ||
IBM Cloud Pak for Security (CP4S) | <=1.6.0.1 | |
IBM Cloud Pak for Security (CP4S) | <=1.6.0.0 | |
IBM Cloud Pak for Security (CP4S) | <=1.5.0.1 | |
IBM Cloud Pak for Security (CP4S) | <=1.5.0.0 | |
IBM Cloud Pak for Security (CP4S) | <=1.4.0.0 | |
debian/glibc | 2.31-13+deb11u11 2.31-13+deb11u10 2.36-9+deb12u9 2.36-9+deb12u7 2.40-4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10029 is a vulnerability in the GNU C Library (glibc) that could cause a denial of service by overflowing an on-stack buffer.
The severity of CVE-2020-10029 is medium, with a severity value of 5.5.
The affected software versions are glibc 2.27-3ubuntu1.2, glibc 2.30, glibc 2.23-0ubuntu11.2, and various versions of glibc from Debian and IBM Cloud Pak for Security.
To fix CVE-2020-10029, upgrade to the recommended versions of glibc provided by the respective vendors or distribution maintainers.
You can find more information about CVE-2020-10029 on the CVE Mitre website, Ubuntu Security Notices, and NIST National Vulnerability Database.