PT-2017-3080 · Gnu+5 · Gnu C Library+5

Published

2017-10-21

·

Updated

2018-09-26

·

CVE-2017-15804

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GNU C Library (aka glibc or libc6) versions prior to 2.27
Description The issue is related to a buffer overflow in the glob function during unescaping of user names with the ~ operator. This can be exploited by a remote attacker to cause a denial of service or potentially execute arbitrary code.
Recommendations For versions prior to 2.27, update to version 2.27 or later to resolve the issue. As a temporary workaround, consider restricting the use of the ~ operator in user names to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2516
ALT-PU-2017-2833
BDU:2017-02450
BDU:2021-06342
CESA-2018_0805
CESA-2018_1879
CVE-2017-15804
MGASA-2017-0464
MGASA-2017-0470
OPENSUSE-SU-2018_0089-1
RHSA-2018:0805
RHSA-2018:1879
RHSA-2018_0805
RHSA-2018_1879
SUSE-SU-2018:0074-1
SUSE-SU-2018:2185-1
SUSE-SU-2018:2187-1
SUSE-SU-2018:2883-1
USN-3534-1

Affected Products

Alt Linux
Centos
Gnu C Library
Red Hat
Suse
Ubuntu