CVE-1999-0199 describes a documentation flaw in the GNU C Library (glibc) prior to version 2.2, specifically concerning the 'tdelete' function. The missing documentation about the return value when deleting a tree's root could lead to applications accessing dangling pointers. This vulnerability is rated as Critical (CVSS 9.8) due to its potential for complete compromise of confidentiality, integrity, and availability, with a low attack complexity and no user interaction required. Despite its age and high severity, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. However, the vulnerability has garnered significant community discussion, indicating ongoing interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.2CPE matchmatch criteria | cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.