Security Advisory
CVE-2021-35942
9.1
CRITICAL
Vulnerability Description
The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have been used to ensure correct calculations.
Published Date
July 22, 2021
Official Source
NIST NVD Advisory