Total vulnerabilities in the database
The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.
Software | From | Fixed in |
---|---|---|
oracle / communications_cloud_native_core_network_function_cloud_native_environment | 22.1.0 | 22.1.0.x |
oracle / communications_cloud_native_core_binding_support_function | 22.1.3 | 22.1.3.x |
oracle / communications_cloud_native_core_network_repository_function | 22.2.0 | 22.2.0.x |
oracle / communications_cloud_native_core_security_edge_protection_proxy | 22.1.1 | 22.1.1.x |
oracle / communications_cloud_native_core_network_repository_function | 22.1.2 | 22.1.2.x |
oracle / enterprise_operations_monitor | 4.3 | 4.3.x |
oracle / enterprise_operations_monitor | 4.4 | 4.4.x |
oracle / enterprise_operations_monitor | 5.0 | 5.0.x |
oracle / communications_cloud_native_core_unified_data_repository | 22.2.0 | 22.2.0.x |
debian / debian_linux | 10.0 | 10.0.x |
gnu / glibc | - | 2.31 |