« Volver al listado

CVE-2019-1010022

Estado: ModificadaCrítica (9.8)—

GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-1010022",
  "cveTags": [
    {
      "tags": [
        "disputed"
      ],
      "sourceIdentifier": "josh@bress.net"
    }
  ],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2019-1010022",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-04-24T16:01:23.968883Z"
        }
      }
    ],
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "josh@bress.net",
      "affectedData": [
        {
          "vendor": "GNU C Library",
          "product": "glibc",
          "versions": [
            {
              "status": "affected",
              "version": "current (At least as of 2018-02-16)"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-07-15T04:15:13.317",
  "references": [
    {
      "url": "https://security-tracker.debian.org/tracker/CVE-2019-1010022",
      "source": "josh@bress.net"
    },
    {
      "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=22850",
      "tags": [
        "Exploit",
        "Issue Tracking",
        "Third Party Advisory"
      ],
      "source": "josh@bress.net"
    },
    {
      "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=22850#c3",
      "source": "josh@bress.net"
    },
    {
      "url": "https://ubuntu.com/security/CVE-2019-1010022",
      "source": "josh@bress.net"
    },
    {
      "url": "https://security-tracker.debian.org/tracker/CVE-2019-1010022",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=22850",
      "tags": [
        "Exploit",
        "Issue Tracking",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=22850#c3",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://ubuntu.com/security/CVE-2019-1010022",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."
    },
    {
      "lang": "es",
      "value": "** EN DISPUTA ** La biblioteca Libc actual de GNU está afectada por: Omisión de Mitigación. El impacto es: El atacante puede omitir la protección stack guard. El componente es: nptl. El vector de ataque es: explotar la vulnerabilidad de desbordamiento del búfer de la pila y utilizar esta vulnerabilidad de omisión para eludir la protección stack guard. NOTA: Los comentarios de los usuarios indican que \"esto está siendo tratado como un error de no seguridad y no una amenaza real\"."
    }
  ],
  "lastModified": "2026-06-17T02:09:43.957",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gnu:glibc:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "68D5A70D-5CEE-4E19-BF35-0245A0E0F6BC"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "josh@bress.net"
}