peter bassill · operator
$ cve CVE-2011-2702 JSON

CVE-2011-2702 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 8.5% (pctl 95)

Patch early

A public exploit exists.

Description

Integer signedness error in Glibc before 2.13 and eglibc before 2.13, when using Supplemental Streaming SIMD Extensions 3 (SSSE3) optimization, allows context-dependent attackers to execute arbitrary code via a negative length parameter to (1) memcpy-ssse3-rep.S, (2) memcpy-ssse3.S, or (3) memset-sse2.S in sysdeps/i386/i686/multiarch/, which triggers an out-of-bounds read, as demonstrated using the memcpy function.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS8.46% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2014-10-27
Last modified2026-06-16

Affected (2)

VendorProduct
gnueglibc
gnuglibc

Public exploits

SourceTitleDate
exploit-dbeGlibc - Signedness Code Execution2012-08-01

References

→ the Explorer  ·  watch your stack  ·  NVD