CVE-2018-1000001

Priority
High
Description
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by
realpath() which can be used to write before the destination buffer leading
to a buffer underflow and potential code execution.
Ubuntu-Description
libc does not account for all the possible return values from the
kernel getcwd(2) syscall; arbitrary code execution may result from
applications making further assumptions on the return value from the
getcwd(3) libary function.
References
Bugs
Notes
 sarnold> I wonder where Go, busybox, and similar "do it ourselves" tools fit.
  I added dietlibc and musl to this page out of an abundance of caution. Someone
  should investigate.
 sbeattie> introduced a regression in glusterfs geo-rep due to its usage
  of rsync. See redhat bug for compensating patch for rsync.
Package
Upstream:needed
Ubuntu 12.04 ESM (Precise Pangolin):released (2.15-0ubuntu10.21)
Ubuntu 14.04 LTS (Trusty Tahr):released (2.19-0ubuntu6.14)
Ubuntu 16.04 LTS (Xenial Xerus):DNE
Ubuntu 17.10 (Artful Aardvark):DNE
Ubuntu 18.04 LTS (Bionic Beaver):DNE
Package
Source: glibc (LP Ubuntu Debian)
Upstream:needed
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):released (2.23-0ubuntu10)
Ubuntu 17.10 (Artful Aardvark):released (2.26-0ubuntu2.1)
Ubuntu 18.04 LTS (Bionic Beaver):not-affected (2.26-0ubuntu2.1)
Patches:
Upstream:https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=52a713fdd0a30e1bd79818e2e3c4ab44ddca1a94
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):needs-triage
Ubuntu 16.04 LTS (Xenial Xerus):needs-triage
Ubuntu 17.10 (Artful Aardvark):needs-triage
Ubuntu 18.04 LTS (Bionic Beaver):needs-triage
Package
Source: musl (LP Ubuntu Debian)
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):needs-triage
Ubuntu 16.04 LTS (Xenial Xerus):needs-triage
Ubuntu 17.10 (Artful Aardvark):needs-triage
Ubuntu 18.04 LTS (Bionic Beaver):needs-triage
More Information

Updated: 2018-02-22 01:14:20 UTC (commit 14252)