Lucene search

K
cve[email protected]CVE-2015-1473
HistoryApr 08, 2015 - 10:59 a.m.

CVE-2015-1473

2015-04-0810:59:03
CWE-119
web.nvd.nist.gov
74
cve-2015-1473
glibc
alloca function
denial of service
segmentation violation
nvd

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

7.1 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

71.4%

The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during a risk-management decision for use of the alloca function, which might allow context-dependent attackers to cause a denial of service (segmentation violation) or overwrite memory locations beyond the stack boundary via a long line containing wide characters that are improperly handled in a wscanf call.

Affected configurations

NVD
Node
canonicalubuntu_linuxMatch10.04lts
OR
canonicalubuntu_linuxMatch12.04lts
OR
canonicalubuntu_linuxMatch14.04lts
OR
canonicalubuntu_linuxMatch14.10
Node
gnuglibcRange2.20

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

7.1 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

71.4%