Vulnerability CVE-2015-8984: Information
Description
The fnmatch function in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent attackers to cause a denial of service (application crash) via a malformed pattern, which triggers an out-of-bounds read.
Severity: MEDIUM (5.9) Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
glibc | sisyphus | 2.22-alt1 | 2.38.0.76.e9f05fa1c6-alt1 | ALT-PU-2015-2084-1 | 153835 | Fixed |
glibc | p10 | 2.22-alt1 | 2.32-alt5.p10.3 | ALT-PU-2015-2084-1 | 153835 | Fixed |
glibc | p9 | 2.22-alt1 | 2.27-alt14 | ALT-PU-2015-2084-1 | 153835 | Fixed |
glibc | c10f1 | 2.22-alt1 | 2.32-alt5.p10.3 | ALT-PU-2015-2084-1 | 153835 | Fixed |
glibc | c9f2 | 2.22-alt1 | 2.27-alt14 | ALT-PU-2015-2084-1 | 153835 | Fixed |
glibc | c7 | 2.17-alt5.M70C.13 | 2.17-alt5.M70C.14 | ALT-PU-2017-2198-1 | 188136 | Fixed |
glibc | p11 | 2.22-alt1 | 2.38.0.76.e9f05fa1c6-alt1 | ALT-PU-2015-2084-1 | 153835 | Fixed |
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
[libc-alpha] 20150814 The GNU C Library version 2.22 is now available |
|
https://sourceware.org/bugzilla/show_bug.cgi?id=18032 |
|
72789 |
|
[oss-security] 20170214 Re: Pending CVE requests for glibc |
|
[oss-security] 20150226 CVE request: glibc: potential application crash due to overread in fnmatch |
|
https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=4a28f4d55a6cc33474c0792fe93b5942d81bf185 |