CVE-2021-35942

Description

The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have been used to ensure correct calculations.

Risk Information

Base Score
9.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS Score
Exploitation Probability
1.109

Associated Vulnerability

VulnerabilityOS Platform
SUSE-SU-2021:2480-1(SUSE Linux Enterprise Server 12-SP5 ) glibc-2.22-114.12.1.x86_64.rpmLinux
SUSE-SU-2021:2480-1(SUSE Linux Enterprise Server 12-SP5 ) glibc-32bit-2.22-114.12.1.x86_64.rpmLinux
SUSE-SU-2021:2480-1(SUSE Linux Enterprise Server 12-SP5 ) glibc-debuginfo-2.22-114.12.1.x86_64.rpmLinux
SUSE-SU-2021:2480-1(SUSE Linux Enterprise Server 12-SP5 ) glibc-debuginfo-32bit-2.22-114.12.1.x86_64.rpmLinux
SUSE-SU-2021:2480-1(SUSE Linux Enterprise Server 12-SP5 ) glibc-debugsource-2.22-114.12.1.x86_64.rpmLinux
SUSE-SU-2021:2480-1(SUSE Linux Enterprise Server 12-SP5 ) glibc-devel-2.22-114.12.1.x86_64.rpmLinux
SUSE-SU-2021:2480-1(SUSE Linux Enterprise Server 12-SP5 ) glibc-devel-32bit-2.22-114.12.1.x86_64.rpmLinux
SUSE-SU-2021:2480-1(SUSE Linux Enterprise Server 12-SP5 ) glibc-devel-debuginfo-2.22-114.12.1.x86_64.rpmLinux
SUSE-SU-2021:2480-1(SUSE Linux Enterprise Server 12-SP5 ) glibc-devel-debuginfo-32bit-2.22-114.12.1.x86_64.rpmLinux
SUSE-SU-2021:2480-1(SUSE Linux Enterprise Server 12-SP5 ) glibc-html-2.22-114.12.1.noarch.rpmLinux
SUSE-SU-2021:2480-1(SUSE Linux Enterprise Server 12-SP5 ) glibc-i18ndata-2.22-114.12.1.noarch.rpmLinux
SUSE-SU-2021:2480-1(SUSE Linux Enterprise Server 12-SP5 ) glibc-info-2.22-114.12.1.noarch.rpmLinux
SUSE-SU-2021:2480-1(SUSE Linux Enterprise Server 12-SP5 ) glibc-locale-2.22-114.12.1.x86_64.rpmLinux
SUSE-SU-2021:2480-1(SUSE Linux Enterprise Server 12-SP5 ) glibc-locale-32bit-2.22-114.12.1.x86_64.rpmLinux
SUSE-SU-2021:2480-1(SUSE Linux Enterprise Server 12-SP5 ) glibc-locale-debuginfo-2.22-114.12.1.x86_64.rpmLinux
SUSE-SU-2021:2480-1(SUSE Linux Enterprise Server 12-SP5 ) glibc-locale-debuginfo-32bit-2.22-114.12.1.x86_64.rpmLinux
SUSE-SU-2021:2480-1(SUSE Linux Enterprise Server 12-SP5 ) glibc-profile-2.22-114.12.1.x86_64.rpmLinux
SUSE-SU-2021:2480-1(SUSE Linux Enterprise Server 12-SP5 ) glibc-profile-32bit-2.22-114.12.1.x86_64.rpmLinux
SUSE-SU-2021:2480-1(SUSE Linux Enterprise Server 12-SP5 ) nscd-2.22-114.12.1.x86_64.rpmLinux
SUSE-SU-2021:2480-1(SUSE Linux Enterprise Server 12-SP5 ) nscd-debuginfo-2.22-114.12.1.x86_64.rpmLinux
GNU C Library (USN-5310-1) libc6_2.27-3ubuntu1.5_i386.debLinux
GNU C Library (USN-5310-1) libc6_2.27-3ubuntu1.5_amd64.debLinux
GNU C Library (USN-5310-1) libc6_2.31-0ubuntu9.9_i386.debLinux
GNU C Library (USN-5310-1) libc6_2.31-0ubuntu9.7_amd64.debLinux
GNU C Library (USN-5310-1) libc6_2.34-0ubuntu3.2_i386.debLinux
GNU C Library (USN-5310-1) libc6_2.34-0ubuntu3.2_amd64.debLinux
Integer Overflow or Wraparound Vulnerability (CVE-2021-35942)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234