Stack-based buffer overflow in GNU C Library (glibc) - CVE-2018-20796
Published: February 28, 2019 / Updated: April 7, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to boundary error in check_dst_limits_calc_pos_1() function in posix/regexec.c. A local user can pass specially crafted arguments to the application, trigger stack overflow and perform denial of service attack.
Affected software
Cognos Dashboards on Cloud Pak for Data
Netcool Operations Insight
IBM Cloud Transformation Advisor
How to mitigate CVE-2018-20796
Netcool Operations Insight - update to 1.6.8
IBM Cloud Transformation Advisor - update to 3.10.0