CVE-2015-1473
published 2015-04-08CVE-2015-1473: The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during a…
PriorityP429medium6.4CVSS 2.0
AVNACLAuNCNIPAP
EPSS
2.13%
80.0th percentile
The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during a risk-management decision for use of the alloca function, which might allow context-dependent attackers to cause a denial of service (segmentation violation) or overwrite memory locations beyond the stack boundary via a long line containing wide characters that are improperly handled in a wscanf call.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | glibc | < glibc 2.19-15 (bookworm) | glibc 2.19-15 (bookworm) |
| eglibc | eglibc | >= 0 < 2.19-0ubuntu6.6 | 2.19-0ubuntu6.6 |
| gnu | glibc | <= 2.20 | — |
| gnu | glibc | >= 0 < 2.19-15 | 2.19-15 |
| gnu | glibc | >= 0 < 2.19-15 | 2.19-15 |
| gnu | glibc | >= 0 < 2.19-15 | 2.19-15 |
| gnu | glibc | >= 0 < 2.19-15 | 2.19-15 |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
osv6.4MEDIUM
vendor_debian6.4MEDIUM
vendor_redhat6.4MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jx9c-49v7-hj5h: The ADDW macro in stdio-common/vfscanf
ghsa_unreviewed·2022-05-17
CVE-2015-1473 [MEDIUM] CWE-119 GHSA-jx9c-49v7-hj5h: The ADDW macro in stdio-common/vfscanf
The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during a risk-management decision for use of the alloca function, which might allow context-dependent attackers to cause a denial of service (segmentation violation) or overwrite memory locations beyond the stack boundary via a long line containing wide characters that are improperly handled in a wscanf call.
OSV
CVE-2015-1473: The ADDW macro in stdio-common/vfscanf
osv·2015-04-08·CVSS 6.4
CVE-2015-1473 [MEDIUM] CVE-2015-1473: The ADDW macro in stdio-common/vfscanf
The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during a risk-management decision for use of the alloca function, which might allow context-dependent attackers to cause a denial of service (segmentation violation) or overwrite memory locations beyond the stack boundary via a long line containing wide characters that are improperly handled in a wscanf call.
OSV
eglibc, glibc vulnerabilities
osv·2015-02-26·CVSS 5.0
CVE-2013-7423 [MEDIUM] eglibc, glibc vulnerabilities
eglibc, glibc vulnerabilities
Arnaud Le Blanc discovered that the GNU C Library incorrectly handled file
descriptors when resolving DNS queries under high load. This may cause a
denial of service in other applications, or an information leak. This issue
only affected Ubuntu 10.04 LTS, Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.
(CVE-2013-7423)
It was discovered that the GNU C Library incorrectly handled receiving a
positive answer while processing the network name when performing DNS
resolution. A remote attacker could use this issue to cause the GNU C
Library to hang, resulting in a denial of service. (CVE-2014-9402)
Joseph Myers discovered that the GNU C Library wscanf function incorrectly
handled memory. A remote attacker could possibly use this issue to cause
the GNU C Library to crash,
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2015-02-26·CVSS 5.0
CVE-2013-7423 [MEDIUM] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in the GNU C Library.
Arnaud Le Blanc discovered that the GNU C Library incorrectly handled file
descriptors when resolving DNS queries under high load. This may cause a
denial of service in other applications, or an information leak. This issue
only affected Ubuntu 10.04 LTS, Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.
(CVE-2013-7423)
It was discovered that the GNU C Library incorrectly handled receiving a
positive answer while processing the network name when performing DNS
resolution. A remote attacker could use this issue to cause the GNU C
Library to hang, resulting in a denial of service. (CVE-2014-9402)
Joseph Myers discovered that the GNU C Library wscanf function incorrectly
handled memory. A remote at
Debian
CVE-2015-1473: glibc - The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc...
vendor_debian·2015·CVSS 6.4
CVE-2015-1473 [MEDIUM] CVE-2015-1473: glibc - The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc...
The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during a risk-management decision for use of the alloca function, which might allow context-dependent attackers to cause a denial of service (segmentation violation) or overwrite memory locations beyond the stack boundary via a long line containing wide characters that are improperly handled in a wscanf call.
Scope: local
bookworm: resolved (fixed in 2.19-15)
bullseye: resolved (fixed in 2.19-15)
forky: resolved (fixed in 2.19-15)
sid: resolved (fixed in 2.19-15)
trixie: resolved (fixed in 2.19-15)
Red Hat
glibc: Stack-overflow in glibc swscanf
vendor_redhat·2014-02-21·CVSS 6.4
CVE-2015-1473 [MEDIUM] CWE-121 glibc: Stack-overflow in glibc swscanf
glibc: Stack-overflow in glibc swscanf
The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during a risk-management decision for use of the alloca function, which might allow context-dependent attackers to cause a denial of service (segmentation violation) or overwrite memory locations beyond the stack boundary via a long line containing wide characters that are improperly handled in a wscanf call.
A stack overflow flaw was found in glibc's swscanf() function. An attacker able to make an application call the swscanf() function could use this flaw to crash that application or, potentially, execute arbitrary code with the permissions of the user running the application.
Statement: This issue does not affe
No detection rules found.
No public exploits indexed.
arXiv
Binary Debloating for Security via Demand Driven Loading
arxiv_fulltext·2019-02-18
Binary Debloating for Security via Demand Driven Loading
Binary Debloating for Security via Demand Driven Loading
Girish Mururu
[email protected]
Georgia Institute of Technology
Chris Porter
[email protected]
Georgia Institute of Technology
Prithayan Barua
[email protected]
Georgia Institute of Technology
Santosh Pande
[email protected]
Georgia Institute of Technology
## Abstract
Modern software systems heavily use C/C++ based libraries.
Because of the weak memory model of C/C++, libraries may suffer from
vulnerabilities which can expose the applications to potential attacks. For example, a very
large number of return oriented programming gadgets exist in glibc that allow
stitching together semantically valid but malicious Turing-complete programs.
In spite of significant advances in attack detection and
mitigat
Bugzilla
CVE-2015-1473 glibc: Stack-overflow in glibc swscanf
bugzilla·2015-04-06·CVSS 7.5
CVE-2015-1473 [HIGH] CVE-2015-1473 glibc: Stack-overflow in glibc swscanf
CVE-2015-1473 glibc: Stack-overflow in glibc swscanf
It was found that the malloc fallback logic when running *scanf() does not have happen at the precise moment (scanf choses between heap and stack), this can lead to a stack-overflow in certain configurations.
Reference:
https://security-tracker.debian.org/tracker/CVE-2015-1473
Discussion:
This report is a duplicate of bug 1188235 - (CVE-2015-1472) CVE-2015-1472 glibc: heap buffer overflow in glibc swscanf.
---
(In reply to Martin Sebor from comment #2)
> This report is a duplicate of bug 1188235 - (CVE-2015-1472) CVE-2015-1472
> glibc: heap buffer overflow in glibc swscanf.
Not as per debian, see difference between:
https://security-tracker.debian.org/tracker/CVE-2015-1472 and
https://security-tracker.debian.org/tracker/CVE-2015
http://openwall.com/lists/oss-security/2015/02/04/1http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/72499http://www.ubuntu.com/usn/USN-2519-1https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commit%3Bh=5bd80bfe9ca0d955bfbbc002781bc7b01b6bcb06http://openwall.com/lists/oss-security/2015/02/04/1http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/72499http://www.ubuntu.com/usn/USN-2519-1https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commit%3Bh=5bd80bfe9ca0d955bfbbc002781bc7b01b6bcb06
2015-04-08
Published