Do your applications use this vulnerable package?
Test your applications
Overview
The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.
References
CVSS Score
4.3
low severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredLow
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityNone
-
IntegrityNone
-
AvailabilityLow
- CVE
- CVE-2010-4756
- CWE
- CWE-399
- Snyk ID
- SNYK-DEBIAN9-GLIBC-356734
- Disclosed
- 02 Mar, 2011
- Published
- 02 Mar, 2011