musl libc through 1.1.23 has an x87 floating-point stack adjustment imbalance, related to the math/i386/ directory. In some cases, use of this library could introduce out-of-bounds writes that are not present in an application's source code.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.openwall.com/lists/musl/2019/08/06/1 | mailing list patch exploit third party advisory |
http://www.openwall.com/lists/oss-security/2019/08/06/4 | mailing list patch exploit third party advisory |
https://security.gentoo.org/glsa/202003-13 | third party advisory vendor advisory |