Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-5229

Опубликовано: 21 авг. 2015
Источник: redhat
CVSS2: 2.6
EPSS Низкий

Описание

The calloc function in the glibc package in Red Hat Enterprise Linux (RHEL) 6.7 and 7.2 does not properly initialize memory areas, which might allow context-dependent attackers to cause a denial of service (hang or crash) via unspecified vectors.

It was discovered that the calloc implementation in glibc could return memory areas which contain non-zero bytes. This could result in unexpected application behavior such as hangs or crashes.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5glibcNot affected
Red Hat Enterprise Linux 6glibcFixedRHBA-2015:146522.07.2015
Red Hat Enterprise Linux 7glibcFixedRHSA-2016:017616.02.2016

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=1256285glibc: calloc may return non-zero memory

EPSS

Процентиль: 76%
0.01
Низкий

2.6 Low

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 9 лет назад

The calloc function in the glibc package in Red Hat Enterprise Linux (RHEL) 6.7 and 7.2 does not properly initialize memory areas, which might allow context-dependent attackers to cause a denial of service (hang or crash) via unspecified vectors.

CVSS3: 7.5
nvd
больше 9 лет назад

The calloc function in the glibc package in Red Hat Enterprise Linux (RHEL) 6.7 and 7.2 does not properly initialize memory areas, which might allow context-dependent attackers to cause a denial of service (hang or crash) via unspecified vectors.

CVSS3: 7.5
debian
больше 9 лет назад

The calloc function in the glibc package in Red Hat Enterprise Linux ( ...

CVSS3: 7.5
github
больше 3 лет назад

The calloc function in the glibc package in Red Hat Enterprise Linux (RHEL) 6.7 and 7.2 does not properly initialize memory areas, which might allow context-dependent attackers to cause a denial of service (hang or crash) via unspecified vectors.

oracle-oval
больше 9 лет назад

ELSA-2016-0176: glibc security and bug fix update (CRITICAL)

EPSS

Процентиль: 76%
0.01
Низкий

2.6 Low

CVSS2