Aller au contenu

Fiche vulnérabilité

CVE-2021-35942 : faille critique gnu glibc (CVSS 9.1)

Description

The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have been used to ensure correct calculations.

En bref

Sévérité
Critique (CVSS 9.1)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Exploitation active
Non signalée par la CISA
Publication
22 juil. 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • gnu glibc
  • netapp active iq unified manager
  • netapp e-series santricity os controller
  • netapp hci management node
  • netapp ontap select deploy administration utility
  • netapp solidfire
  • debian debian linux

Références

Rechercher une autre vulnérabilité dans la base CVE