Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-8982

Опубликовано: 15 мар. 2017
Источник: ubuntu
Приоритет: medium
CVSS2: 6.8
CVSS3: 8.1

Описание

Integer overflow in the strxfrm function in the GNU C Library (aka glibc or libc6) before 2.21 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string, which triggers a stack-based buffer overflow.

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

released

2.19-0ubuntu6.10
precise

released

2.15-0ubuntu10.16
trusty

released

2.19-0ubuntu6.10
trusty/esm

released

2.19-0ubuntu6.10
upstream

needs-triage

vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

xenial

DNE

yakkety

DNE

Показывать по

РелизСтатусПримечание
devel

not-affected

2.23-0ubuntu3
esm-infra-legacy/trusty

DNE

esm-infra/xenial

not-affected

2.23-0ubuntu3
precise

DNE

trusty

DNE

trusty/esm

DNE

upstream

released

2.21
vivid/stable-phone-overlay

not-affected

2.21-0ubuntu4
vivid/ubuntu-core

not-affected

2.21-0ubuntu4
xenial

not-affected

2.23-0ubuntu3

Показывать по

6.8 Medium

CVSS2

8.1 High

CVSS3

Связанные уязвимости

redhat
почти 11 лет назад

Integer overflow in the strxfrm function in the GNU C Library (aka glibc or libc6) before 2.21 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string, which triggers a stack-based buffer overflow.

CVSS3: 8.1
nvd
почти 9 лет назад

Integer overflow in the strxfrm function in the GNU C Library (aka glibc or libc6) before 2.21 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string, which triggers a stack-based buffer overflow.

CVSS3: 8.1
debian
почти 9 лет назад

Integer overflow in the strxfrm function in the GNU C Library (aka gli ...

CVSS3: 8.1
github
больше 3 лет назад

Integer overflow in the strxfrm function in the GNU C Library (aka glibc or libc6) before 2.21 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string, which triggers a stack-based buffer overflow.

fstec
почти 9 лет назад

Уязвимость библиотеки, обеспечивающей системные вызовы и основные функции glibc, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код

6.8 Medium

CVSS2

8.1 High

CVSS3