Описание
In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-insensitive regular-expression match.
Ссылки
- Broken Link
- ExploitMailing ListVendor Advisory
- ExploitMailing ListVendor Advisory
- Third Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- Issue TrackingPatchThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Not Applicable
- Broken Link
- ExploitMailing ListVendor Advisory
- ExploitMailing ListVendor Advisory
- Third Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- Issue TrackingPatchThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.29 (включая)
cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*
Конфигурация 2
Одно из
cpe:2.3:a:netapp:cloud_backup:*:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:steelstore_cloud_integrated_storage:-:*:*:*:*:*:*:*
Конфигурация 3Версия от 7.7.2.0 (включая) до 7.7.2.21 (исключая)Версия от 7.8.2.0 (включая) до 7.8.2.8 (исключая)Версия от 8.0.0 (включая) до 8.1.1 (исключая)
Одно из
cpe:2.3:a:mcafee:web_gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:mcafee:web_gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:mcafee:web_gateway:*:*:*:*:*:*:*:*
Конфигурация 4
Одно из
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*
EPSS
Процентиль: 93%
0.11071
Средний
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-125
Связанные уязвимости
CVSS3: 9.8
ubuntu
больше 6 лет назад
In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-insensitive regular-expression match.
CVSS3: 6.5
redhat
больше 6 лет назад
In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-insensitive regular-expression match.
CVSS3: 9.8
debian
больше 6 лет назад
In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_n ...
EPSS
Процентиль: 93%
0.11071
Средний
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-125