跳转到帖子

Amazon Linux 2023: CVE-2020-35357: Medium priority package update for gsl

recommended_posts

发布于
  • Members

Amazon Linux 2023: CVE-2020-35357: Medium priority package update for gsl

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
08/22/2023
Created
02/14/2025
Added
02/14/2025
Modified
02/14/2025

Description

A buffer overflow can occur when calculating the quantile value using the Statistics Library of GSL (GNU Scientific Library), versions 2.5 and 2.6. Processing a maliciously crafted input data for gsl_stats_quantile_from_sorted_data of the library may lead to unexpected application termination or arbitrary code execution. A stack buffer overflow flaw was found in the gsl package due to a lack of validation of the user controlled fraction parameter. This issue may allow an attacker to craft malicious input, leading to a segmentation fault and further Denial of Service. Since the buffer overflow happens when reading data from the input array, it's very unlikely to achieve arbitrary code execution using this flaw.

Solution(s)

  • amazon-linux-2023-upgrade-gsl
  • amazon-linux-2023-upgrade-gsl-debuginfo
  • amazon-linux-2023-upgrade-gsl-debugsource
  • amazon-linux-2023-upgrade-gsl-devel

References

  • https://attackerkb.com/topics/cve-2020-35357
  • CVE - 2020-35357
  • https://alas.aws.amazon.com/AL2023/ALAS-2023-353.html
  • 查看数 702
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…