First published: Wed Aug 31 2022(Updated: )
An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a crafted input string larger than 1024 bytes, it reads uninitialized memory from the heap and prints it to the target log file, potentially revealing a portion of the contents of the heap.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU C Library (glibc) | =2.37 | |
GNU C Library (glibc) | =2.36 | |
GNU glibc | =2.36 | |
All of | ||
Netapp H300s Firmware | ||
Netapp H300s | ||
All of | ||
Netapp H500s Firmware | ||
Netapp H500s | ||
All of | ||
Netapp H700s Firmware | ||
Netapp H700s | ||
All of | ||
Netapp H410s Firmware | ||
Netapp H410s | ||
All of | ||
Netapp H410c Firmware | ||
Netapp H410c | ||
NetApp ONTAP Select Deploy administration utility | ||
Netapp H300s Firmware | ||
Netapp H300s | ||
Netapp H500s Firmware | ||
Netapp H500s | ||
Netapp H700s Firmware | ||
Netapp H700s | ||
Netapp H410s Firmware | ||
Netapp H410s | ||
Netapp H410c Firmware | ||
Netapp H410c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-39046 is an issue discovered in the GNU C Library (glibc) 2.36, where the syslog function can potentially reveal uninitialized memory from the heap.
The severity of CVE-2022-39046 is high with a CVSS score of 5.3.
GNU glibc 2.36 and Apple macOS Ventura, Big Sur, and Monterey are affected by CVE-2022-39046.
CVE-2022-39046 can be exploited by passing a crafted input string larger than 1024 bytes to the syslog function.
Yes, patches are available for CVE-2022-39046. Please refer to the references provided for more information.