CVE-2023-0687

Public on 2023-02-06
Modified on 2023-03-24
Description
A vulnerability was found in GNU C Library 2.38. It has been declared as critical. This vulnerability affects the function __monstartup of the file gmon.c of the component Call Graph Monitor. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. VDB-220246 is the identifier assigned to this vulnerability.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
9.8
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 1 glibc Not Affected
Amazon Linux 2 - Core glibc Not Affected
Amazon Linux 2023 glibc Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NVD CVSSv2 4.0 AV:A/AC:H/Au:S/C:P/I:P/A:P
NVD CVSSv3 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H