The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.
2022-01-14T07:15:08.867
2025-05-05T17:17:55.843
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gnu | glibc | < 2.31 | Yes |
Application | oracle | communications_cloud_native_core_binding_support_function | 22.1.3 | Yes |
Application | oracle | communications_cloud_native_core_network_function_cloud_native_environment | 22.1.0 | Yes |
Application | oracle | communications_cloud_native_core_network_repository_function | 22.1.2 | Yes |
Application | oracle | communications_cloud_native_core_network_repository_function | 22.2.0 | Yes |
Application | oracle | communications_cloud_native_core_security_edge_protection_proxy | 22.1.1 | Yes |
Application | oracle | communications_cloud_native_core_unified_data_repository | 22.2.0 | Yes |
Application | oracle | enterprise_operations_monitor | 4.3 | Yes |
Application | oracle | enterprise_operations_monitor | 4.4 | Yes |
Application | oracle | enterprise_operations_monitor | 5.0 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |