[Secure-testing-team] Bug#879500: CVE-2017-15671

Moritz Muehlenhoff jmm at debian.org
Sun Oct 22 10:44:47 UTC 2017


Package: libc6
Version: 2.24-17
Severity: important
Tags: security

Please see http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15671:
The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27,
when invoked with GLOB_TILDE, could skip freeing allocated memory when processing
the ~ operator with a long user name, potentially leading to a denial of
service (memory leak).

Upstream bug is https://sourceware.org/bugzilla/show_bug.cgi?id=22325

Fix is here: https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=c66c908230169c1bab1f83b071eb585baa214b9f

Cheers,
        Moritz



More information about the Secure-testing-team mailing list