Out-of-bounds write in musl libc - CVE-2019-14697
Published: April 27, 2020
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to x87 floating-point stack adjustment imbalance, related to the math/i386/ directory. A remote attacker can pass specially crafted data to the application, trigger out-of-bounds write and execute arbitrary code on the target system.
Affected software
Gentoo Linux
Ubuntu
musl (Alpine package)
musl-dev (Ubuntu package)
musl (Ubuntu package)
How to mitigate CVE-2019-14697
musl (Alpine package) - update to 1.1.18-r4
musl-dev (Ubuntu package) - update to Ubuntu Pro
musl (Ubuntu package) - update to Ubuntu Pro