cisco-sa-20160218-glibc

Vulnerability in GNU glibc Affecting Cisco Products: February 2016

High · Updated · Cisco

48 products with CSAF evidence

On February 16, 2016, an industry-wide, critical vulnerability in the GNU C library (glibc) was publicly disclosed. Multiple Cisco products incorporate a version of glibc that may be affected by the vulnerability. The vulnerability could allow an unauthenticated, remote attacker to trigger a buffer overflow condition that may result in a denial of service (DoS) condition or allow the attacker to execute arbitrary code on an affected device. Cisco will release software updates that address this vulnerability. Workarounds that address this vulnerability are not available.