« List of all CVEs

CVE-2011-1071

Published: 4/8/2011 Last updated: 8/6/2024 Reserved: 2/24/2011

The GNU C Library (aka glibc or libc6) before 2.12.2 and Embedded GLIBC (EGLIBC) allow context-dependent attackers to execute arbitrary code or cause a denial of service (memory consumption) via a long UTF8 string that is used in an fnmatch call, aka a "stack extension attack," a related issue to CVE-2010-2898, CVE-2010-1917, and CVE-2007-4782, as originally reported for use of this library by Google Chrome.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Opam packages affected (1)

gettext-stub

Products affected (1)

Product Vendor Version
n/a n/a < 21.3R3-S6

References (50)