CVE Vulnerabilities

CVE-2009-5029

Published: May 02, 2013 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
6.5 MODERATE
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

Integer overflow in the __tzfile_read function in glibc before 2.15 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted timezone (TZ) file, as demonstrated using vsftpd.

Affected Software

Name Vendor Start Version End Version
Glibc Gnu * 2.14 (including)
Glibc Gnu 2.0 (including) 2.0 (including)
Glibc Gnu 2.0.1 (including) 2.0.1 (including)
Glibc Gnu 2.0.2 (including) 2.0.2 (including)
Glibc Gnu 2.0.3 (including) 2.0.3 (including)
Glibc Gnu 2.0.4 (including) 2.0.4 (including)
Glibc Gnu 2.0.5 (including) 2.0.5 (including)
Glibc Gnu 2.0.6 (including) 2.0.6 (including)
Glibc Gnu 2.1 (including) 2.1 (including)
Glibc Gnu 2.1.1 (including) 2.1.1 (including)
Glibc Gnu 2.1.1.6 (including) 2.1.1.6 (including)
Glibc Gnu 2.1.2 (including) 2.1.2 (including)
Glibc Gnu 2.1.3 (including) 2.1.3 (including)
Glibc Gnu 2.1.9 (including) 2.1.9 (including)
Glibc Gnu 2.13 (including) 2.13 (including)
Red Hat Enterprise Linux 4 RedHat glibc-0:2.3.4-2.57 *
Red Hat Enterprise Linux 5 RedHat glibc-0:2.5-65.el5_7.3 *
Red Hat Enterprise Linux 6 RedHat glibc-0:2.12-1.47.el6_2.5 *
Eglibc Ubuntu devel *
Eglibc Ubuntu lucid *
Eglibc Ubuntu maverick *
Eglibc Ubuntu natty *
Eglibc Ubuntu oneiric *
Eglibc Ubuntu upstream *
Glibc Ubuntu hardy *

References