Do your applications use this vulnerable package?
Test your applications
Overview
The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input to an 80-bit long double function contains a non-canonical bit pattern, a seen when passing a 0x5d414141414141410000 value to sinl on x86 targets. This is related to sysdeps/ieee754/ldbl-96/e_rem_pio2l.c.
References
CVSS Score
5.5
medium severity
-
Attack VectorLocal
-
Attack ComplexityLow
-
Privileges RequiredLow
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityNone
-
IntegrityNone
-
AvailabilityHigh
- CVE
- CVE-2020-10029
- CWE
- CWE-119
- Snyk ID
- SNYK-DEBIAN10-GLIBC-559181
- Disclosed
- 04 Mar, 2020
- Published
- 04 Mar, 2020