CVE-2011-2702
Publication date 20 July 2011
Last updated 24 July 2024
Ubuntu priority
Description
Integer signedness error in Glibc before 2.13 and eglibc before 2.13, when using Supplemental Streaming SIMD Extensions 3 (SSSE3) optimization, allows context-dependent attackers to execute arbitrary code via a negative length parameter to (1) memcpy-ssse3-rep.S, (2) memcpy-ssse3.S, or (3) memset-sse2.S in sysdeps/i386/i686/multiarch/, which triggers an out-of-bounds read, as demonstrated using the memcpy function.
Status
Package | Ubuntu Release | Status |
---|---|---|
eglibc | ||
glibc | ||
Notes
Patch details
Package | Patch details |
---|---|
eglibc | |
glibc |
References
Related Ubuntu Security Notices (USN)
- USN-1396-1
- GNU C Library vulnerabilities
- 9 March 2012