Vulnerability record · CVE-2023-0687 · published 6 February 2023
CVE-2023-0687: Gnu glibc classic buffer overflow vulnerability
Gnu · Glibc
A vulnerability was found in GNU C Library 2.38. It has been declared as critical. This vulnerability affects the function __monstartup of the file gmon.c of the component Call Graph Monitor. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. VDB-220246 is the identifier assigned to this vulnerability. NOTE: The real existence of this vulnerability is still doubted at the moment. The inputs that induce this vulnerability are basically addresses of the running application that is built with gmon enabled. It's basically trusted input or input that needs an actual security flaw to be compromised or controlled.
Description
A vulnerability was found in GNU C Library 2.38. It has been declared as critical. This vulnerability affects the function __monstartup of the file gmon.c of the component Call Graph Monitor. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. VDB-220246 is the identifier assigned to this vulnerability. NOTE: The real existence of this vulnerability is still doubted at the moment. The inputs that induce this vulnerability are basically addresses of the running application that is built with gmon enabled. It's basically trusted input or input that needs an actual security flaw to be compromised or controlled.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://patchwork.sourceware.org/project/glibc/patch/20230204114138.5436-1-leo%40yuriev.ru/ | Patch |
| https://sourceware.org/bugzilla/show_bug.cgi?id=29444 | Issue TrackingPatchThird Party Advisory |
| https://vuldb.com/?ctiid.220246 | Permissions RequiredThird Party Advisory |
| https://vuldb.com/?id.220246 | Permissions RequiredThird Party Advisory |
| https://patchwork.sourceware.org/project/glibc/patch/20230204114138.5436-1-leo%40yuriev.ru/ | Patch |
| https://sourceware.org/bugzilla/show_bug.cgi?id=29444 | Issue TrackingPatchThird Party Advisory |
| https://vuldb.com/?ctiid.220246 | Permissions RequiredThird Party Advisory |
| https://vuldb.com/?id.220246 | Permissions RequiredThird Party Advisory |
Track CVE-2023-0687 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-0687), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.