Information disclosure in Glibc - CVE-2019-1010025
Published: July 15, 2019 / Updated: August 8, 2020
Glibc
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
** DISPUTED ** GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is "ASLR bypass itself is not a vulnerability."