PT-2015-7848 · Gnu+2 · Gnu C Library+2

Kostya Serebryany

·

Published

2015-12-09

·

Updated

2023-07-31

·

CVE-2015-8984

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GNU C Library versions prior to 2.22
Description The issue allows context-dependent attackers to cause a denial of service, resulting in an application crash, by providing a malformed pattern that triggers an out-of-bounds read in the fnmatch function.
Recommendations For versions prior to 2.22, update to version 2.22 or later to resolve the issue. As a temporary workaround, consider restricting the input to the fnmatch function to prevent malformed patterns from being processed.

Exploit

Fix

DoS

Out of bounds Read

Weakness Enumeration

Related Identifiers

ALT-PU-2015-2084
CVE-2015-8984
DLA-316-1
USN-3239-1
USN-3239-2

Affected Products

Alt Linux
Gnu C Library
Ubuntu