[Secure-testing-team] Bug#879501: CVE-2017-15670
Moritz Muehlenhoff
jmm at debian.org
Sun Oct 22 10:46:54 UTC 2017
Package: libc6
Version: 2.24-17
Severity: important
Tags: security
Please see http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15670:
The GNU C Library (aka glibc or libc6) before 2.27 contains an off-by-one
error leading to a heap-based buffer overflow in the glob function in
glob.c, related to the processing of home directories using the ~ operator
followed by a long string.
Bug is here: https://sourceware.org/bugzilla/show_bug.cgi?id=22320
Fixes:
https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=c369d66e5426a30e4725b100d5cd28e372754f90 (master)
https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=a76376df7c07e577a9515c3faa5dbd50bda5da07 (release/2.26/master)
Cheers,
Moritz
More information about the Secure-testing-team
mailing list