First published: Wed Dec 07 2011(Updated: )
There exists a integer overflow to buffer overflow vulnerability within __tzfile_read function of the GNU C Library. This vulnerability was published by dividead early in 2009 in the following blog post: <a href="http://dividead.wordpress.com/2009/06/01/glibc-timezone-integer-overflow/">http://dividead.wordpress.com/2009/06/01/glibc-timezone-integer-overflow/</a> In December 3, Kingcope, at Full Disclosure Mailing List, noted vsftpd as one possible attack vector for this issue: <a href="http://lists.grok.org.uk/pipermail/full-disclosure/2011-December/084452.html">http://lists.grok.org.uk/pipermail/full-disclosure/2011-December/084452.html</a>
Affected Software | Affected Version | How to fix |
---|---|---|
GNU C Library | ||
vsftpd |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.