CVE-2014-4043
glibc < 2.20 - Use-After-Free via posix_spawn_file_actions_addopen Path Argument
Title source: llmDescription
The posix_spawn_file_actions_addopen function in glibc before 2.20 does not copy its path argument in accordance with the POSIX specification, which allows context-dependent attackers to trigger use-after-free vulnerabilities.
References (16)
Core 16
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/68006
Patch x_refsource_confirm
https://sourceware.org/bugzilla/show_bug.cgi?id=17048
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/93784
Exploit x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1109263
Patch x_refsource_confirm
https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=89e435f3559c53084498e9baad22172b64429362
Third Party Advisory vendor-advisory
x_refsource_gentoo
https://security.gentoo.org/glsa/201503-04
Vendor Advisory vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2014:152
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00012.html
Mailing List mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2019/Jun/18
Mailing List mailing-list
x_refsource_bugtraq
https://seclists.org/bugtraq/2019/Jun/14
Exploit, Third Party Advisory x_refsource_misc
http://packetstormsecurity.com/files/153278/WAGO-852-Industrial-Managed-Switch-Series-Code-Execution-Hardcoded-Credentials.html
Mailing List mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2019/Sep/7
Mailing List mailing-list
x_refsource_bugtraq
https://seclists.org/bugtraq/2019/Sep/7
Exploit, Third Party Advisory x_refsource_misc
http://packetstormsecurity.com/files/154361/Cisco-Device-Hardcoded-Credentials-GNU-glibc-BusyBox.html
Scores
EPSS
0.0164
EPSS Percentile
82.2%
Details
CWE
CWE-94
Status
published
Products (2)
gnu/glibc
< 2.19
opensuse/opensuse
13.1
Published
Oct 06, 2014
Tracked Since
Feb 18, 2026