cve/2018/CVE-2018-1000001.md
2024-07-25 21:25:12 +00:00

2.4 KiB

CVE-2018-1000001

Description

In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destination buffer leading to a buffer underflow and potential code execution.

POC

Reference

Github