glibc: two vulnerabilities
| Package(s): | glibc | CVE #(s): | CVE-2015-1472 CVE-2015-1473 | ||||||||||||||||||||||||||||||||||||||||||||||||
| Created: | February 18, 2015 | Updated: | February 18, 2015 | ||||||||||||||||||||||||||||||||||||||||||||||||
| Description: | From the Mageia advisory:
Under certain conditions wscanf can allocate too little memory for the to-be-scanned arguments and overflow the allocated buffer (CVE-2015-1472). The incorrect use of "__libc_use_alloca (newsize)" caused a different (and weaker) policy to be enforced which could allow a denial of service attack (CVE-2015-1473). | ||||||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||||||
