First published: Thu Nov 18 2021(Updated: )
A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the buffer is exactly 1. A local attacker who can control the input buffer and size passed to getcwd() in a setuid program could use this flaw to potentially execute arbitrary code and escalate their privileges on the system.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
GNU C Library | <2.31 | |
Debian | =10.0 | |
Debian | =11.0 | |
netapp e-series performance analyzer | ||
NetApp NFS Plug-in for VMware VAAI | ||
NetApp ONTAP Select Deploy | ||
netapp h300s firmware | ||
netapp h300s | ||
NetApp H500S Firmware | ||
netapp h500s | ||
netapp h700s firmware | ||
netapp h700s | ||
netapp h410s firmware | ||
netapp h410s | ||
netapp h410c firmware | ||
netapp h410c | ||
All of | ||
netapp h300s firmware | ||
netapp h300s | ||
All of | ||
NetApp H500S Firmware | ||
netapp h500s | ||
All of | ||
netapp h700s firmware | ||
netapp h700s | ||
All of | ||
netapp h410s firmware | ||
netapp h410s | ||
All of | ||
netapp h410c firmware | ||
netapp h410c | ||
debian/glibc | 2.31-13+deb11u11 2.31-13+deb11u10 2.36-9+deb12u9 2.36-9+deb12u7 2.40-7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3999 is a vulnerability in glibc that allows for an off-by-one buffer overflow and underflow in getcwd(), leading to potential memory corruption and arbitrary code execution.
CVE-2021-3999 has a severity rating of 7.8 (High).
CVE-2021-3999 affects glibc versions 2.28-10+deb10u2, 2.31-13+deb11u6, 2.31-13+deb11u7, 2.36-9+deb12u2, 2.36-9+deb12u3, and 2.37-12.
CVE-2021-3999 can be fixed on Debian Debian Linux 10.0 by updating glibc to version 2.31 or higher.
Yes, Netapp E-series Performance Analyzer and Netapp Nfs Plug-in are affected by CVE-2021-3999.