Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-8776

Опубликовано: 20 сент. 2015
Источник: redhat
CVSS3: 6.5
CVSS2: 4

Описание

The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range time value.

It was found that out-of-range time values passed to the strftime() function could result in an out-of-bounds memory access. This could lead to application crash or, potentially, information disclosure.

Меры по смягчению последствий

Check time values before they are passed to strftime, or call strftime only with struct tm values computed by gmtime or localtime.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5compat-glibcWill not fix
Red Hat Enterprise Linux 5glibcWill not fix
Red Hat Enterprise Linux 6compat-glibcWill not fix
Red Hat Enterprise Linux 7compat-glibcWill not fix
Red Hat Enterprise Linux 6glibcFixedRHSA-2017:068021.03.2017
Red Hat Enterprise Linux 7glibcFixedRHSA-2017:191601.08.2017

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1300299glibc: Segmentation fault caused by passing out-of-range data to strftime()

6.5 Medium

CVSS3

4 Medium

CVSS2

Связанные уязвимости

CVSS3: 9.1
ubuntu
больше 9 лет назад

The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range time value.

CVSS3: 9.1
nvd
больше 9 лет назад

The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range time value.

CVSS3: 9.1
debian
больше 9 лет назад

The strftime function in the GNU C Library (aka glibc or libc6) before ...

CVSS3: 9.1
github
больше 3 лет назад

The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range time value.

oracle-oval
больше 8 лет назад

ELSA-2017-0680: glibc security and bug fix update (MODERATE)

6.5 Medium

CVSS3

4 Medium

CVSS2