CVE-2010-4756: Medium severity IBM Cognos Analytics vulnerability
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-4756 to the following vulnerability:
Name: CVE-2010-4756 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4756 Assigned: 20110302 Reference: http://securityreason.com/achievementsecurityalert/89 Reference: http://cxib.net/stuff/glob-0day.c Reference: http://securityreason.com/exploitalert/9223
The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.
Other sources
GNU C Library is vulnerable to a denial of service, caused by an error in the glob implementation. A remote authenticated attacker could exploit this vulnerability using a specially-crafted glob expression to consume all available CPU resources.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4756?
CVE-2010-4756 is classified as a medium severity vulnerability.
How do I fix CVE-2010-4756?
To fix CVE-2010-4756, apply the latest security patches provided by IBM for Cognos Analytics.
Which versions of IBM Cognos Analytics are affected by CVE-2010-4756?
CVE-2010-4756 affects IBM Cognos Analytics versions up to and including 12.0.2 and 11.2.4 FP3.
Does CVE-2010-4756 affect the GNU C Library (glibc)?
Yes, CVE-2010-4756 also affects various versions of the GNU C Library (glibc).
What type of vulnerability is CVE-2010-4756?
CVE-2010-4756 is a remote code execution vulnerability that may lead to unauthorized access.