|
|
Log in / Subscribe / Register

glibc: two vulnerabilities

Package(s):glibc CVE #(s):CVE-2015-1472 CVE-2015-1473
Created:February 18, 2015 Updated:February 18, 2015
Description: From the Mageia advisory:

Under certain conditions wscanf can allocate too little memory for the to-be-scanned arguments and overflow the allocated buffer (CVE-2015-1472).

The incorrect use of "__libc_use_alloca (newsize)" caused a different (and weaker) policy to be enforced which could allow a denial of service attack (CVE-2015-1473).

Alerts:
Gentoo 201602-02 glibc 2016-02-17
Scientific Linux SLSA-2015:2199-7 glibc 2015-12-21
Red Hat RHSA-2015:2589-01 glibc 2015-12-09
Oracle ELSA-2015-2199 glibc 2015-11-25
Red Hat RHSA-2015:2199-07 glibc 2015-11-19
Mandriva MDVSA-2015:168 glibc 2015-03-30
openSUSE openSUSE-SU-2015:0351-1 glibc 2015-02-23
Debian DSA-3169-1 eglibc 2015-02-23
Debian-LTS DLA-165-1 eglibc 2015-03-06
Mageia MGASA-2015-0072 glibc 2015-02-17
Fedora FEDORA-2015-2837 glibc 2015-03-04
Ubuntu USN-2519-1 eglibc, glibc 2015-02-26

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds