Back

MEDIUM

glibc: __fortify_fail may use corrupted memory when called from SSP callback

Published Oct 12, 2010

Description

Certain run-time memory protection mechanisms in the GNU C Library (aka glibc or libc6) print argv[0] and backtrace information, which might allow context-dependent attackers to obtain sensitive information from process memory by executing an incorrect program, as demonstrated by a setuid program that contains a stack-based buffer overflow error, related to the __fortify_fail function in debug/fortify_fail.c, and the __stack_chk_fail (aka stack protection) and __chk_fail (aka FORTIFY_SOURCE) implementations.

Affected products

Remediation

Red Hat statement

The Red Hat Security Response Team has rated this issue as having low security impact. We do not currently plan to fix this flaw. If more information becomes available at a future date, we may revisit the issue.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 12, 2010
Updated Sep 16, 2024
Reserved Aug 31, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Apr 27, 2010