[Secure-testing-team] Bug#879501: CVE-2017-15670

Moritz Muehlenhoff jmm at debian.org
Sun Oct 22 10:46:54 UTC 2017


Package: libc6
Version: 2.24-17
Severity: important
Tags: security

Please see http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15670:
The GNU C Library (aka glibc or libc6) before 2.27 contains an off-by-one
error leading to a heap-based buffer overflow in the glob function in
glob.c, related to the processing of home directories using the ~ operator
followed by a long string.

Bug is here: https://sourceware.org/bugzilla/show_bug.cgi?id=22320

Fixes:
https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=c369d66e5426a30e4725b100d5cd28e372754f90 (master)
https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=a76376df7c07e577a9515c3faa5dbd50bda5da07 (release/2.26/master)

Cheers,
        Moritz



More information about the Secure-testing-team mailing list