← Back to CVE List

CVE-2005-3590

Published: 2019-04-10T20:29Z
Last Modified: 2024-11-21T00:02Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The getgrouplist function in the GNU C library (glibc) before version 2.3.5, when invoked with a zero argument, writes to the passed pointer even if the specified array size is zero, leading to a buffer overflow and potentially allowing attackers to corrupt memory. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt