Input validation error in GNU C Library (glibc) - CVE-2019-6488
Published: January 22, 2019 / Updated: March 1, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in __memmove_avx_unaligned_erms in sysdeps/x86_64/multiarch/memmove-vec-unaligned-erms.S during a memcpy due to application that runs on the x32 architecture incorrectly attempts to use a 64-bit register for size_t in assembly codes. A remote attacker can pass specially crafted data to the application using an affected library and cause segmentation fault.
Affected software
Gentoo Linux
Netcool Operations Insight
IBM Cloud Transformation Advisor
How to mitigate CVE-2019-6488
Netcool Operations Insight - update to 1.6.8
IBM Cloud Transformation Advisor - update to 3.10.0