CVE-2014-4043

The posix_spawn_file_actions_addopen function in glibc before 2.20 does not copy its path argument in accordance with the POSIX specification, which allows context-dependent attackers to trigger use-after-free vulnerabilities.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
Affected Products (NVD)
VendorProductVersion
gnuglibc
𝑥
≤ 2.19
opensuseopensuse
13.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
glibc
bookworm
2.36-9+deb12u8
fixed
bookworm (security)
2.36-9+deb12u7
fixed
bullseye
2.31-13+deb11u11
fixed
bullseye (security)
2.31-13+deb11u10
fixed
sid
2.40-3
fixed
trixie
2.40-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
eglibc
lucid
Fixed 2.11.1-0ubuntu7.14
released
precise
Fixed 2.15-0ubuntu10.6
released
saucy
ignored
trusty
Fixed 2.19-0ubuntu6.1
released
glibc
lucid
dne
precise
dne
saucy
dne
trusty
dne
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
glibc
suse enterprise desktop 15
2.26-11.8
fixed
suse enterprise desktop 15 SP1
2.26-13.19.1
fixed
suse enterprise sap 12 SP5
2.22-100.15.4
fixed
suse enterprise sap 15
2.26-11.8
fixed
suse enterprise sap 15 SP1
2.26-13.19.1
fixed
suse enterprise server 12 SP5
2.22-100.15.4
fixed
suse enterprise server 15
2.26-11.8
fixed
suse enterprise server 15 SP1
2.26-13.19.1
fixed
glibc-32bit
suse enterprise desktop 15
2.26-11.8
fixed
suse enterprise desktop 15 SP1
2.26-13.19.1
fixed
suse enterprise desktop 15 SP2
2.26-8.21
fixed
suse enterprise sap 12 SP5
2.22-100.15.4
fixed
suse enterprise sap 15
2.26-11.8
fixed
suse enterprise sap 15 SP1
2.26-13.19.1
fixed
suse enterprise sap 15 SP2
2.26-8.21
fixed
suse enterprise server 12 SP5
2.22-100.15.4
fixed
suse enterprise server 15
2.26-11.8
fixed
suse enterprise server 15 SP1
2.26-13.19.1
fixed
suse enterprise server 15 SP2
2.26-8.21
fixed
glibc-devel
suse enterprise desktop 15
2.26-11.8
fixed
suse enterprise desktop 15 SP1
2.26-13.19.1
fixed
suse enterprise sap 12 SP5
2.22-100.15.4
fixed
suse enterprise sap 15
2.26-11.8
fixed
suse enterprise sap 15 SP1
2.26-13.19.1
fixed
suse enterprise server 12 SP5
2.22-100.15.4
fixed
suse enterprise server 15
2.26-11.8
fixed
suse enterprise server 15 SP1
2.26-13.19.1
fixed
glibc-devel-32bit
suse enterprise desktop 15
2.26-11.8
fixed
suse enterprise desktop 15 SP1
2.26-8.21
fixed
suse enterprise sap 12 SP5
2.22-100.15.4
fixed
suse enterprise sap 15
2.26-11.8
fixed
suse enterprise sap 15 SP1
2.26-8.21
fixed
suse enterprise server 12 SP5
2.22-100.15.4
fixed
suse enterprise server 15
2.26-11.8
fixed
suse enterprise server 15 SP1
2.26-8.21
fixed
glibc-devel-static
suse enterprise desktop 15
2.26-11.8
fixed
suse enterprise desktop 15 SP1
2.26-13.19.1
fixed
suse enterprise sap 15
2.26-11.8
fixed
suse enterprise sap 15 SP1
2.26-13.19.1
fixed
suse enterprise server 15
2.26-11.8
fixed
suse enterprise server 15 SP1
2.26-13.19.1
fixed
glibc-extra
suse enterprise desktop 15
2.26-11.8
fixed
suse enterprise desktop 15 SP1
2.26-13.19.1
fixed
suse enterprise sap 15
2.26-11.8
fixed
suse enterprise sap 15 SP1
2.26-13.19.1
fixed
suse enterprise server 15
2.26-11.8
fixed
suse enterprise server 15 SP1
2.26-13.19.1
fixed
glibc-html
suse enterprise sap 12 SP5
2.22-100.15.4
fixed
suse enterprise server 12 SP5
2.22-100.15.4
fixed
glibc-i18ndata
suse enterprise desktop 15
2.26-11.8
fixed
suse enterprise desktop 15 SP1
2.26-13.19.1
fixed
suse enterprise sap 12 SP5
2.22-100.15.4
fixed
suse enterprise sap 15
2.26-11.8
fixed
suse enterprise sap 15 SP1
2.26-13.19.1
fixed
suse enterprise server 12 SP5
2.22-100.15.4
fixed
suse enterprise server 15
2.26-11.8
fixed
suse enterprise server 15 SP1
2.26-13.19.1
fixed
glibc-info
suse enterprise desktop 15
2.26-11.8
fixed
suse enterprise desktop 15 SP1
2.26-13.19.1
fixed
suse enterprise sap 12 SP5
2.22-100.15.4
fixed
suse enterprise sap 15
2.26-11.8
fixed
suse enterprise sap 15 SP1
2.26-13.19.1
fixed
suse enterprise server 12 SP5
2.22-100.15.4
fixed
suse enterprise server 15
2.26-11.8
fixed
suse enterprise server 15 SP1
2.26-13.19.1
fixed
glibc-locale
suse enterprise desktop 15
2.26-11.8
fixed
suse enterprise desktop 15 SP1
2.26-13.19.1
fixed
suse enterprise sap 12 SP5
2.22-100.15.4
fixed
suse enterprise sap 15
2.26-11.8
fixed
suse enterprise sap 15 SP1
2.26-13.19.1
fixed
suse enterprise server 12 SP5
2.22-100.15.4
fixed
suse enterprise server 15
2.26-11.8
fixed
suse enterprise server 15 SP1
2.26-13.19.1
fixed
glibc-locale-32bit
suse enterprise desktop 15
2.26-11.8
fixed
suse enterprise desktop 15 SP1
2.26-8.21
fixed
suse enterprise desktop 15 SP2
2.26-8.21
fixed
suse enterprise sap 12 SP5
2.22-100.15.4
fixed
suse enterprise sap 15
2.26-11.8
fixed
suse enterprise sap 15 SP1
2.26-8.21
fixed
suse enterprise sap 15 SP2
2.26-8.21
fixed
suse enterprise server 12 SP5
2.22-100.15.4
fixed
suse enterprise server 15
2.26-11.8
fixed
suse enterprise server 15 SP1
2.26-8.21
fixed
suse enterprise server 15 SP2
2.26-8.21
fixed
glibc-locale-base
suse enterprise desktop 15 SP1
2.26-13.19.1
fixed
suse enterprise sap 15 SP1
2.26-13.19.1
fixed
suse enterprise server 15 SP1
2.26-13.19.1
fixed
glibc-profile
suse enterprise desktop 15
2.26-11.8
fixed
suse enterprise desktop 15 SP1
2.26-13.19.1
fixed
suse enterprise sap 12 SP5
2.22-100.15.4
fixed
suse enterprise sap 15
2.26-11.8
fixed
suse enterprise sap 15 SP1
2.26-13.19.1
fixed
suse enterprise server 12 SP5
2.22-100.15.4
fixed
suse enterprise server 15
2.26-11.8
fixed
suse enterprise server 15 SP1
2.26-13.19.1
fixed
glibc-profile-32bit
suse enterprise sap 12 SP5
2.22-100.15.4
fixed
suse enterprise server 12 SP5
2.22-100.15.4
fixed
glibc-utils
suse enterprise desktop 15
2.26-11.8
fixed
suse enterprise desktop 15 SP1
2.26-13.19.1
fixed
suse enterprise sap 15
2.26-11.8
fixed
suse enterprise sap 15 SP1
2.26-13.19.1
fixed
suse enterprise server 15
2.26-11.8
fixed
suse enterprise server 15 SP1
2.26-13.19.1
fixed
nscd
suse enterprise desktop 15
2.26-11.8
fixed
suse enterprise desktop 15 SP1
2.26-13.19.1
fixed
suse enterprise sap 12 SP5
2.22-100.15.4
fixed
suse enterprise sap 15
2.26-11.8
fixed
suse enterprise sap 15 SP1
2.26-13.19.1
fixed
suse enterprise server 12 SP5
2.22-100.15.4
fixed
suse enterprise server 15
2.26-11.8
fixed
suse enterprise server 15 SP1
2.26-13.19.1
fixed
References