PT-2015-5309 · Gnu+5 · Gnu C Library+5

Joseph Myers

·

Published

2015-02-05

·

Updated

2024-06-15

·

CVE-2015-1472

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GNU C Library (aka glibc or libc6) versions prior to 2.21
Description The issue allows context-dependent attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long line containing wide characters that are improperly handled in a wscanf call. This occurs due to the ADDW macro in stdio-common/vfscanf.c not properly considering data-type size during memory allocation.
Recommendations For GNU C Library (aka glibc or libc6) versions prior to 2.21, update to version 2.21 or later to resolve the issue.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-2084
CESA-2015_2199
CVE-2015-1472
DLA-165-1
DSA-3169-1
MGASA-2015-0072
OPENSUSE-SU-2024:10154-1
RHSA-2015:2199
RHSA-2015:2589
RHSA-2015_2199
SUSE-RU-2015:0794-1
SUSE-SU-2015:0253-1
SUSE-SU-2015:0439-1
SUSE-SU-2015:0526-1
SUSE-SU-2015:0551-1
USN-2519-1

Affected Products

Alt Linux
Centos
Gnu C Library
Red Hat
Suse
Ubuntu