An issue in newlib v.4.3.0 allows an attacker to execute arbitrary code via the time unit scaling in the _gettimeofday function.
{ "binaries": [ { "binary_name": "libnewlib-arm-none-eabi", "binary_version": "4.4.0.20231231-2" }, { "binary_name": "libnewlib-dev", "binary_version": "4.4.0.20231231-2" }, { "binary_name": "libnewlib-doc", "binary_version": "4.4.0.20231231-2" }, { "binary_name": "newlib-source", "binary_version": "4.4.0.20231231-2" } ], "availability": "No subscription required", "ubuntu_priority": "medium" }