First published: Wed Aug 31 2022(Updated: )
An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a crafted input string larger than 1024 bytes, it reads uninitialized memory from the heap and prints it to the target log file, potentially revealing a portion of the contents of the heap.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU C Library | =2.37 | |
GNU C Library | =2.36 | |
GNU C Library | =2.36 | |
All of | ||
netapp h300s firmware | ||
netapp h300s | ||
All of | ||
NetApp H500S Firmware | ||
netapp h500s | ||
All of | ||
netapp h700s firmware | ||
netapp h700s | ||
All of | ||
netapp h410s firmware | ||
netapp h410s | ||
All of | ||
netapp h410c firmware | ||
netapp h410c | ||
NetApp ONTAP Select Deploy | ||
netapp h300s firmware | ||
netapp h300s | ||
NetApp H500S Firmware | ||
netapp h500s | ||
netapp h700s firmware | ||
netapp h700s | ||
netapp h410s firmware | ||
netapp h410s | ||
netapp h410c firmware | ||
netapp h410c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-39046 is an issue discovered in the GNU C Library (glibc) 2.36, where the syslog function can potentially reveal uninitialized memory from the heap.
The severity of CVE-2022-39046 is high with a CVSS score of 5.3.
GNU glibc 2.36 and Apple macOS Ventura, Big Sur, and Monterey are affected by CVE-2022-39046.
CVE-2022-39046 can be exploited by passing a crafted input string larger than 1024 bytes to the syslog function.
Yes, patches are available for CVE-2022-39046. Please refer to the references provided for more information.