Qualys TRU Discovers Important Vulnerabilities in GNU C Library’s syslog()
ID: 937abe8d-d006-51b9-9673-e896f18b27ea
STIX ID: report--937abe8d-d006-51b9-9673-e896f18b27ea
Feed Name: Qualys Blog
Threat Score
Qualys Threat Research Unit disclosed multiple serious vulnerabilities in the GNU C Library, most notably a heap-based buffer overflow in __vsyslog_internal (CVE-2023-6246) allowing local privilege escalation to root on many Linux distributions, two additional lesser syslog issues (CVE-2023-6779, CVE-2023-6780), and a qsort() memory corruption due to a missing bounds check; patches and coordinated disclosure details are provided along with Qualys detection and QID coverage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
