A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366.
The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.
Link | Tags |
---|---|
https://www.exploit-db.com/exploits/43331/ | exploit vdb entry third party advisory |
http://seclists.org/oss-sec/2017/q4/385 | mailing list exploit third party advisory |
https://security.netapp.com/advisory/ntap-20190404-0003/ | |
http://www.openwall.com/lists/oss-security/2019/06/27/7 | mailing list |
http://www.openwall.com/lists/oss-security/2019/06/28/1 | mailing list |
http://www.openwall.com/lists/oss-security/2019/06/28/2 | mailing list |