CVE-2015-1472
published 2015-04-08CVE-2015-1472: The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during memory…
PriorityP336high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.69%
90.8th percentile
The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during memory allocation, which allows context-dependent attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long line containing wide characters that are improperly handled in a wscanf call.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | glibc | < glibc 2.19-15 (bookworm) | glibc 2.19-15 (bookworm) |
| eglibc | eglibc | >= 0 < 2.19-0ubuntu6.6 | 2.19-0ubuntu6.6 |
| gnu | glibc | <= 2.20 | — |
| gnu | glibc | >= 0 < 2.19-15 | 2.19-15 |
| gnu | glibc | >= 0 < 2.19-15 | 2.19-15 |
| gnu | glibc | >= 0 < 2.19-15 | 2.19-15 |
| gnu | glibc | >= 0 < 2.19-15 | 2.19-15 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7g3j-xr9q-w6cw: The ADDW macro in stdio-common/vfscanf
ghsa_unreviewed·2022-05-14
CVE-2015-1472 [HIGH] CWE-119 GHSA-7g3j-xr9q-w6cw: The ADDW macro in stdio-common/vfscanf
The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during memory allocation, which allows context-dependent attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long line containing wide characters that are improperly handled in a wscanf call.
OSV
CVE-2015-1472: The ADDW macro in stdio-common/vfscanf
osv·2015-04-08·CVSS 7.5
CVE-2015-1472 [HIGH] CVE-2015-1472: The ADDW macro in stdio-common/vfscanf
The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during memory allocation, which allows context-dependent attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long line containing wide characters that are improperly handled in a wscanf call.
OSV
eglibc, glibc vulnerabilities
osv·2015-02-26·CVSS 5.0
CVE-2013-7423 [MEDIUM] eglibc, glibc vulnerabilities
eglibc, glibc vulnerabilities
Arnaud Le Blanc discovered that the GNU C Library incorrectly handled file
descriptors when resolving DNS queries under high load. This may cause a
denial of service in other applications, or an information leak. This issue
only affected Ubuntu 10.04 LTS, Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.
(CVE-2013-7423)
It was discovered that the GNU C Library incorrectly handled receiving a
positive answer while processing the network name when performing DNS
resolution. A remote attacker could use this issue to cause the GNU C
Library to hang, resulting in a denial of service. (CVE-2014-9402)
Joseph Myers discovered that the GNU C Library wscanf function incorrectly
handled memory. A remote attacker could possibly use this issue to cause
the GNU C Library to crash,
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2015-02-26·CVSS 5.0
CVE-2013-7423 [MEDIUM] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in the GNU C Library.
Arnaud Le Blanc discovered that the GNU C Library incorrectly handled file
descriptors when resolving DNS queries under high load. This may cause a
denial of service in other applications, or an information leak. This issue
only affected Ubuntu 10.04 LTS, Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.
(CVE-2013-7423)
It was discovered that the GNU C Library incorrectly handled receiving a
positive answer while processing the network name when performing DNS
resolution. A remote attacker could use this issue to cause the GNU C
Library to hang, resulting in a denial of service. (CVE-2014-9402)
Joseph Myers discovered that the GNU C Library wscanf function incorrectly
handled memory. A remote at
Debian
CVE-2015-1472: glibc - The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc...
vendor_debian·2015·CVSS 7.5
CVE-2015-1472 [HIGH] CVE-2015-1472: glibc - The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc...
The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during memory allocation, which allows context-dependent attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long line containing wide characters that are improperly handled in a wscanf call.
Scope: local
bookworm: resolved (fixed in 2.19-15)
bullseye: resolved (fixed in 2.19-15)
forky: resolved (fixed in 2.19-15)
sid: resolved (fixed in 2.19-15)
trixie: resolved (fixed in 2.19-15)
Red Hat
glibc: heap buffer overflow in glibc swscanf
vendor_redhat·2014-02-21·CVSS 7.5
CVE-2015-1472 [HIGH] CWE-122 glibc: heap buffer overflow in glibc swscanf
glibc: heap buffer overflow in glibc swscanf
The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during memory allocation, which allows context-dependent attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long line containing wide characters that are improperly handled in a wscanf call.
A heap-based buffer overflow flaw was found in glibc's swscanf() function. An attacker able to make an application call the swscanf() function could use this flaw to crash that application or, potentially, execute arbitrary code with the permissions of the user running the application.
Statement: This issue did not affect the versions of glibc as shipped with Red Hat
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1473 glibc: Stack-overflow in glibc swscanf
bugzilla·2015-04-06·CVSS 7.5
CVE-2015-1473 [HIGH] CVE-2015-1473 glibc: Stack-overflow in glibc swscanf
CVE-2015-1473 glibc: Stack-overflow in glibc swscanf
It was found that the malloc fallback logic when running *scanf() does not have happen at the precise moment (scanf choses between heap and stack), this can lead to a stack-overflow in certain configurations.
Reference:
https://security-tracker.debian.org/tracker/CVE-2015-1473
Discussion:
This report is a duplicate of bug 1188235 - (CVE-2015-1472) CVE-2015-1472 glibc: heap buffer overflow in glibc swscanf.
---
(In reply to Martin Sebor from comment #2)
> This report is a duplicate of bug 1188235 - (CVE-2015-1472) CVE-2015-1472
> glibc: heap buffer overflow in glibc swscanf.
Not as per debian, see difference between:
https://security-tracker.debian.org/tracker/CVE-2015-1472 and
https://security-tracker.debian.org/tracker/CVE-2015
Bugzilla
CVE-2015-1472 glibc: heap buffer overflow in glibc swscanf
bugzilla·2015-02-02·CVSS 7.5
CVE-2015-1472 [HIGH] CVE-2015-1472 glibc: heap buffer overflow in glibc swscanf
CVE-2015-1472 glibc: heap buffer overflow in glibc swscanf
Heap buffer overflow was reported [1] in glibc stdio-common/vfscanf.c.
stdio-common/vfscanf.c has an ADDW macro that tries to determine whether to use malloc or alloca for allocations. But in the malloc case, it only allocates newsize bytes instead of the required newsize * sizeof (CHAR_T). Thus the allocated buffer gets overrun in the wide-string case, as shown in the following testcase:
int
main (void)
{
wchar_t *s = malloc ((SIZE + 1) * sizeof (*s));
if (s == NULL)
abort ();
for (size_t i = 0; i
Date: Fri Feb 6 00:30:42 2015 -0500
CVE-2015-1472: wscanf allocates too little memory
BZ #16618
Under certain conditions wscanf can allocate too little memory for the
to-be-scanned arguments and overflow the allocated buffer. The
i
http://openwall.com/lists/oss-security/2015/02/04/1http://packetstormsecurity.com/files/153278/WAGO-852-Industrial-Managed-Switch-Series-Code-Execution-Hardcoded-Credentials.htmlhttp://packetstormsecurity.com/files/154361/Cisco-Device-Hardcoded-Credentials-GNU-glibc-BusyBox.htmlhttp://seclists.org/fulldisclosure/2019/Jun/18http://seclists.org/fulldisclosure/2019/Sep/7http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/72428http://www.ubuntu.com/usn/USN-2519-1https://seclists.org/bugtraq/2019/Jun/14https://seclists.org/bugtraq/2019/Sep/7https://security.gentoo.org/glsa/201602-02https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commit%3Bh=5bd80bfe9ca0d955bfbbc002781bc7b01b6bcb06https://sourceware.org/ml/libc-alpha/2015-02/msg00119.htmlhttp://openwall.com/lists/oss-security/2015/02/04/1http://packetstormsecurity.com/files/153278/WAGO-852-Industrial-Managed-Switch-Series-Code-Execution-Hardcoded-Credentials.htmlhttp://packetstormsecurity.com/files/154361/Cisco-Device-Hardcoded-Credentials-GNU-glibc-BusyBox.htmlhttp://seclists.org/fulldisclosure/2019/Jun/18http://seclists.org/fulldisclosure/2019/Sep/7http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/72428http://www.ubuntu.com/usn/USN-2519-1https://seclists.org/bugtraq/2019/Jun/14https://seclists.org/bugtraq/2019/Sep/7https://security.gentoo.org/glsa/201602-02https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commit%3Bh=5bd80bfe9ca0d955bfbbc002781bc7b01b6bcb06https://sourceware.org/ml/libc-alpha/2015-02/msg00119.html
2015-04-08
Published