CVE-2011-2168
Severity CVSS v4.0:
Pending analysis
Type:
CWE-189
Numeric Errors
Publication date:
24/05/2011
Last modified:
11/04/2025
Description
Multiple integer overflows in the glob implementation in libc in OpenBSD before 4.9 might allow context-dependent attackers to have an unspecified impact via a crafted string, related to the GLOB_APPEND and GLOB_DOOFFS flags, a different issue than CVE-2011-0418.
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:openbsd:openbsd:*:*:*:*:*:*:*:* | 4.8 (including) | |
| cpe:2.3:o:openbsd:openbsd:2.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:2.1:*:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:2.2:*:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:2.3:*:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:2.4:*:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:2.5:*:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:2.6:*:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:2.7:*:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:2.8:*:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:2.9:*:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:3.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:3.1:*:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:3.2:*:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:3.3:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://securityreason.com/achievement_securityalert/97
- http://www.openbsd.org/cgi-bin/cvsweb/src/lib/libc/gen/glob.c#rev1.35
- http://www.openbsd.org/cgi-bin/cvsweb/src/lib/libc/gen/glob.c.diff?r1=1.34%3Br2%3D1.35%3Bf%3Dh
- http://www.securityfocus.com/bid/48004
- http://securityreason.com/achievement_securityalert/97
- http://www.openbsd.org/cgi-bin/cvsweb/src/lib/libc/gen/glob.c#rev1.35
- http://www.openbsd.org/cgi-bin/cvsweb/src/lib/libc/gen/glob.c.diff?r1=1.34%3Br2%3D1.35%3Bf%3Dh
- http://www.securityfocus.com/bid/48004



