PT-2015-5310 · Gnu+4 · Gnu C Library+4

Joseph Myers

·

Published

2015-02-05

·

Updated

2024-06-15

·

CVE-2015-1473

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions GNU C Library versions prior to 2.21
Description The issue is related to the ADDW macro in stdio-common/vfscanf.c, which does not properly consider data-type size during a risk-management decision for use of the alloca function. This might allow attackers to cause a denial of service or overwrite memory locations beyond the stack boundary via a long line containing wide characters that are improperly handled in a wscanf call.
Recommendations For GNU C Library versions prior to 2.21, update to version 2.21 or later to resolve the issue.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-2084
AZL-40934
CESA-2015_2199
CVE-2015-1473
DLA-165-1
DSA-3169-1
MGASA-2015-0072
OPENSUSE-SU-2024:10154-1
RHSA-2015:2199
RHSA-2015:2589
RHSA-2015_2199
USN-2519-1

Affected Products

Alt Linux
Centos
Gnu C Library
Red Hat
Ubuntu