Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33000
HistoryNov 17, 2021 - 10:36 p.m.

Denial Of Service (DoS)

2021-11-1722:36:24
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

0.011 Low

EPSS

Percentile

84.8%

glibc is vulnerable denial of service. This is an integer overflow flaw in wordexp(), caused by a specially crafted untrusted regular expression input. It can result in arbitrary memory read. The upstream glibc project generally does not consider bugs due to untrusted inputs as security issues, but this is an exception since it invokes undefined behaviour in glibc. In general, use of untrusted regular expression input is strongly discouraged.