Lucene search

K
cve[email protected]CVE-2015-5277
HistoryDec 17, 2015 - 7:59 p.m.

CVE-2015-5277

2015-12-1719:59:02
CWE-119
web.nvd.nist.gov
56
cve-2015-5277
get_contents function
nss
glibc
libc6
denial of service
heap corruption
privilege escalation

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.9 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.1%

The get_contents function in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) before 2.20 might allow local users to cause a denial of service (heap corruption) or gain privileges via a long line in the NSS files database.

Affected configurations

NVD
Node
redhatenterprise_linux_desktopMatch7.0
OR
redhatenterprise_linux_hpc_nodeMatch7.0
OR
redhatenterprise_linux_serverMatch7.0
OR
redhatenterprise_linux_workstationMatch7.0
Node
gnuglibcRange2.19
Node
canonicalubuntu_linuxMatch12.04lts
OR
canonicalubuntu_linuxMatch14.04lts
OR
canonicalubuntu_linuxMatch15.10

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.9 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.1%