Do your applications use this vulnerable package?
Test your applications
Overview
An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to return a pointer to a heap area that is too small, potentially leading to heap corruption.
References
CVSS Score
9.8
high severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityHigh
-
AvailabilityHigh
- CVE
- CVE-2018-6485
- CWE
- CWE-190 CWE-787
- Snyk ID
- SNYK-DEBIAN9-GLIBC-356602
- Disclosed
- 01 Feb, 2018
- Published
- 01 Feb, 2018