5 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:N/I:N/A:P
7.5 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
0.006 Low
EPSS
Percentile
79.1%
In the GNU C Library (aka glibc or libc6) through 2.29,
check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion,
as demonstrated by ‘(\227|)(\1\1|t1|\\2537)+’ in grep.
Author | Note |
---|---|
mdeslaur | glibc regex compiler is not supposed to be exposed to untrusted content, and upstream does not consider this to be a security issue: https://sourceware.org/glibc/wiki/Security Exceptions https://lists.gnu.org/r/bug-gnulib/2018-09/msg00068.html as of 2020-06-04, no fix available from upstream. We will not be fixing this issue in Ubuntu, marking as ignored. |
5 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:N/I:N/A:P
7.5 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
0.006 Low
EPSS
Percentile
79.1%