Back

CRITICAL

glibc: buffer overflow in getgrouplist function leading to corrupted memory

Published Apr 10, 2019

Description

The getgrouplist function in the GNU C library (glibc) before version 2.3.5, when invoked with a zero argument, writes to the passed pointer even if the specified array size is zero, leading to a buffer overflow and potentially allowing attackers to corrupt memory.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 10, 2019
Updated Aug 7, 2024
Reserved Apr 10, 2019
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Apr 10, 2019