Lucene search

K
f5F5F5:K16366
HistoryApr 03, 2015 - 12:00 a.m.

K16366 : GNU C Library (glibc) vulnerability CVE-2015-1472

2015-04-0300:00:00
my.f5.com
9

8.5 High

AI Score

Confidence

High

0.015 Low

EPSS

Percentile

86.8%

Security Advisory Description

stdio-common/vfscanf.c has an ADDW macro that tries to determine whether to use malloc or alloca for allocations. But in the malloc case, it only allocates newsize bytes instead of the required newsize * sizeof (CHAR_T). Thus the allocated buffer gets overrun in the wide-string case. (CVE-2015-1472)

Impact

None. F5 products are not affected by this vulnerability.