Lucene search

K
ubuntucveUbuntu.comUB:CVE-2015-20109
HistoryJun 25, 2023 - 12:00 a.m.

CVE-2015-20109

2023-06-2500:00:00
ubuntu.com
ubuntu.com
11
cve-2015-20109
end_pattern
internal_fnmatch
glibc
libc6
denial of service
application crash
fnmatch
linux

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

0.005 Low

EPSS

Percentile

77.5%

end_pattern (called from internal_fnmatch) in the GNU C Library (aka glibc
or libc6) before 2.22 might allow context-dependent attackers to cause a
denial of service (application crash), as demonstrated by use of the
fnmatch library function with the **(!() pattern. NOTE: this is not the
same as CVE-2015-8984; also, some Linux distributions have fixed
CVE-2015-8984 but have not fixed this additional fnmatch issue.

OSVersionArchitecturePackageVersionFilename
ubuntu14.04noarcheglibc< 2.19-0ubuntu6.15+esm3UNKNOWN

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

0.005 Low

EPSS

Percentile

77.5%