Record summary

CVE-2011-1071 has a selected CVSS score of 5.1; EIP currently links 1 catalogued exploit.

Description

The GNU C Library (aka glibc or libc6) before 2.12.2 and Embedded GLIBC (EGLIBC) allow context-dependent attackers to execute arbitrary code or cause a denial of service (memory consumption) via a long UTF8 string that is used in an fnmatch call, aka a "stack extension attack," a related issue to CVE-2010-2898, CVE-2010-1917, and CVE-2007-4782, as originally reported for use of this library by Google Chrome.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBGNU glibc < 2.12.2 - 'fnmatch()' Stack CorruptionExploitDB exploitby Simon Berry-ByrneNot analyzed1 file
ExploitDB

PoC details

References

Showing 12 of 27