An issue was discovered in klibc before 2.0.9. Additions in the malloc() function may result in an integer overflow and a subsequent heap buffer overflow.
{
"binaries": [
{
"binary_name": "klibc-utils",
"binary_version": "2.0.3-0ubuntu1.14.04.3+esm2"
},
{
"binary_name": "libklibc",
"binary_version": "2.0.3-0ubuntu1.14.04.3+esm2"
},
{
"binary_name": "libklibc-dev",
"binary_version": "2.0.3-0ubuntu1.14.04.3+esm2"
}
],
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}
{
"binaries": [
{
"binary_name": "klibc-utils",
"binary_version": "2.0.4-8ubuntu1.16.04.4+esm1"
},
{
"binary_name": "libklibc",
"binary_version": "2.0.4-8ubuntu1.16.04.4+esm1"
},
{
"binary_name": "libklibc-dev",
"binary_version": "2.0.4-8ubuntu1.16.04.4+esm1"
}
],
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}