| » Topic: | Multiple Vendors libc/fnmatch(3) DoS |
» Added by: SecurityReason
» Date: 13.05.2011
New advisory about vulnerabilities in libc for multiple vendors "Multiple Vendors libc/fnmatch(3) DoS (incl apache)". A 'resource exhaustion' vulnerability has been identified in fnmatch(3) function.
Attacker, what may modify first and second parameters(pattern,string) of fnmatch(3), may cause to CPU resource exhaustion.
More:
http://securityreason.com/achievement_securityalert/98
Exploit:
http://cxib.net/stuff/apr_fnmatch.txt
References:
http://cvsweb.netbsd.org/bsdweb.cgi/src/lib/libc/gen/fnmatch.c
https://rhn.redhat.com/errata/RHSA-2011-0507.html
http://httpd.apache.org/security/vulnerabilities_22.html
http://www.apache.org/dist/apr/CHANGES-APR-1.4
http://cwe.mitre.org/data/definitions/399.html
|