PT-2015-5310 · Gnu+4 · Gnu C Library+4

Joseph Myers

·

Publicado

2015-02-05

·

Atualizado

2024-06-15

·

CVE-2015-1473

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions GNU C Library versions prior to 2.21
Description The issue is related to the ADDW macro in stdio-common/vfscanf.c, which does not properly consider data-type size during a risk-management decision for use of the alloca function. This might allow attackers to cause a denial of service or overwrite memory locations beyond the stack boundary via a long line containing wide characters that are improperly handled in a wscanf call.
Recommendations For GNU C Library versions prior to 2.21, update to version 2.21 or later to resolve the issue.

Exploit

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-2084
AZL-40934
CESA-2015_2199
CVE-2015-1473
DLA-165-1
DSA-3169-1
MGASA-2015-0072
OPENSUSE-SU-2024:10154-1
RHSA-2015:2199
RHSA-2015:2589
RHSA-2015_2199
USN-2519-1

Produtos afetados

Alt Linux
Centos
Gnu C Library
Red Hat
Ubuntu