Input validation error in GNU C Library (glibc) - CVE-2019-7309
Published: February 5, 2019 / Updated: March 1, 2019
Vulnerability details
The vulnerability allows a local attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to the memcmp function for the x32 architecture can incorrectly return zero (indicating that the inputs are equal) when the RDX most significant bit is mishandled. A local attacker can supply specially crafted input and cause the application to crash.
Affected software
Gentoo Linux
Netcool Operations Insight
IBM Cloud Transformation Advisor
Robotic Process Automation for Cloud Pak
How to mitigate CVE-2019-7309
Netcool Operations Insight - update to 1.6.8
IBM Cloud Transformation Advisor - update to 3.10.0
Robotic Process Automation for Cloud Pak - update to 21.0.6