Vulnerability Name: | CVE-2019-7309 (CCN-156553) | ||||||||||||||||||||||||||||||||||||||||||||
Assigned: | 2019-02-02 | ||||||||||||||||||||||||||||||||||||||||||||
Published: | 2019-02-02 | ||||||||||||||||||||||||||||||||||||||||||||
Updated: | 2020-08-24 | ||||||||||||||||||||||||||||||||||||||||||||
Summary: | In the GNU C Library (aka glibc or libc6) through 2.29, the memcmp function for the x32 architecture can incorrectly return zero (indicating that the inputs are equal) because the RDX most significant bit is mishandled. | ||||||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) 4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-noinfo | ||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-7309 Source: BID Type: Third Party Advisory, VDB Entry 106835 Source: XF Type: UNKNOWN gnuc-cve20197309-weak-security(156553) Source: GENTOO Type: UNKNOWN GLSA-202006-04 Source: CCN Type: Sourceware Bugzilla Bug 24155 x32 memcmp can treat positive length as 0 (if sign bit in RDX is set) (CVE-2019-7309) Source: MISC Type: Exploit, Issue Tracking, Third Party Advisory https://sourceware.org/bugzilla/show_bug.cgi?id=24155 Source: MISC Type: Mailing List, Third Party Advisory https://sourceware.org/ml/libc-alpha/2019-02/msg00041.html Source: CCN Type: GNU Web site The GNU C Library (glibc) Source: CCN Type: IBM Security Bulletin 1143466 (Watson Studio Local) Multiple Vulnerabilities in GNU C Library affects IBM Watson Studio Local Source: CCN Type: IBM Security Bulletin 6853463 (Robotic Process Automation for Cloud Pak) Multiple Security Vulnerabilities may affect IBM Robotic Process Automation for Cloud Pak. Source: CCN Type: IBM Security Bulletin 6982841 (Netcool Operations Insight) Netcool Operations Insight v1.6.8 addresses multiple security vulnerabilities. Source: CCN Type: WhiteSource Vulnerability Database CVE-2019-7309 | ||||||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||
BACK |