Record summary

CVE-2009-5029 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.

Description

Integer overflow in the __tzfile_read function in glibc before 2.15 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted timezone (TZ) file, as demonstrated using vsftpd.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBGNU glibc - Timezone Parsing Remote Integer OverflowExploitDB exploitby divideadNot analyzed1 file
ExploitDB

PoC details

References

11