PT-2019-1679 · Gnu+7 · Gnu C Library+7

Published

2019-01-20

·

Updated

2024-06-15

·

CVE-2019-9169

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GNU C Library (aka glibc or libc6) versions prior to 2.29
Description The issue is related to a heap-based buffer over-read in the proceed next node function in posix/regexec.c, which occurs during an attempted case-insensitive regular-expression match. This can lead to a denial of service.
Recommendations For GNU C Library (aka glibc or libc6) versions prior to 2.29, update to version 2.29 or later to resolve the issue.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:1585
ALT-PU-2019-3114
BDU:2019-01242
CESA-2021_1585
CVE-2019-9169
OPENSUSE-SU-2024:10792-1
RHSA-2021:1585
RHSA-2021_1585
RLSA-2021:1585
SUSE-SU-2019:1102-1
SUSE-SU-2019:14084-1
SUSE-SU-2019:1877-1
SUSE-SU-2019:1958-1
SUSE-SU-2019:1958-2
SUSE-SU-2019_14084-1
USN-4416-1

Affected Products

Alt Linux
Almalinux
Centos
Gnu C Library
Red Hat
Rocky Linux
Suse
Ubuntu