{
  "modified": "2025-08-09T19:01:26Z",
  "published": "2020-10-06T13:15:13Z",
  "id": "CVE-1999-0199",
  "details": "manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion of a tree's root, which might allow attackers to access a dangling pointer in an application whose developer was unaware of a documentation update from 1999.",
  "severity": [
    {
      "type": "CVSS_V3",
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
    }
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://ftp.gnu.org/gnu/glibc/glibc-2.2.tar.gz"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/bminor/glibc/commit/2864e767053317538feafa815046fff89e5a16be#diff-94e8c502f255fdfc346df0e29fd4ef40"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.cee.studio/tdelete.html"
    },
    {
      "type": "EVIDENCE",
      "url": "https://www.cee.studio/tdelete.html"
    },
    {
      "type": "FIX",
      "url": "https://github.com/bminor/glibc/commit/2864e767053317538feafa815046fff89e5a16be#diff-94e8c502f255fdfc346df0e29fd4ef40"
    },
    {
      "type": "WEB",
      "url": "https://ftp.gnu.org/gnu/glibc/glibc-2.2.tar.gz"
    }
  ]
}
