CRITICAL 9.1 Microsoft
CVE-2021-35942
The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted crafted pattern potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have been used to ensure correct calculations.
Microsoft Security Update 2021-Jul: The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted crafted pattern potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have been used to ensure correct calculations.
Affected Products
- cm1 glibc 2.28-19 on CBL Mariner 1.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-35942
- https://nvd.nist.gov/vuln/detail/CVE-2021-35942
This critical severity vulnerability with a CVSS score of 9.1 was published on 2021-07-13 via Microsoft. Affected: cm1 glibc 2.28-19 on CBL Mariner 1.0.
Risk Timeline
CVE Disclosed2021-07-13 · 1905 days ago
Remediation Resources
Official Advisory
msrc.microsoft.com/update-guide/vulnerability/CVE-2021-35942NVD / MITRE
nvd.nist.gov/vuln/detail/CVE-2021-35942Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2021-33909 PoC | fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not pro | HIGH | 7.8 |
| CVE-2021-35039 | kernel/module.c in the Linux kernel before 5.12.14 mishandles Signature Verifica | HIGH | 7.8 |
| CVE-2021-37576 | arch/powerpc/kvm/book3s_rtas.c in the Linux kernel through 5.13.5 on the powerpc | HIGH | 7.8 |
| CVE-2021-32740 | Regular Expression Denial of Service in Addressable templates | HIGH | 7.5 |
| CVE-2021-32761 | Integer overflow issues with *BIT commands on 32-bit systems | HIGH | 7.5 |
| CVE-2021-36222 | ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Ke | HIGH | 7.5 |
vulnfeed aggregates 12641 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.