CVE-2015-20109
published 2023-06-25CVE-2015-20109: end_pattern (called from internal_fnmatch) in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent attackers to cause a denial of…
PriorityP416medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.32%
24.0th percentile
end_pattern (called from internal_fnmatch) in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent attackers to cause a denial of service (application crash), as demonstrated by use of the fnmatch library function with the **(!() pattern. NOTE: this is not the same as CVE-2015-8984; also, some Linux distributions have fixed CVE-2015-8984 but have not fixed this additional fnmatch issue.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.22-1 (bookworm) | glibc 2.22-1 (bookworm) |
| eglibc | eglibc | >= 0 < 2.19-0ubuntu6.15+esm3 | 2.19-0ubuntu6.15+esm3 |
| gnu | glibc | < 2.22 | 2.22 |
| gnu | glibc | >= 0 < 2.22-1 | 2.22-1 |
| gnu | glibc | >= 0 < 2.22-1 | 2.22-1 |
| gnu | glibc | >= 0 < 2.22-1 | 2.22-1 |
| gnu | glibc | >= 0 < 2.22-1 | 2.22-1 |
| gnu | glibc | >= 0 < 2.23-0ubuntu11.3+esm6 | 2.23-0ubuntu11.3+esm6 |
| gnu | glibc | >= 0 < 2.27-3ubuntu1.6+esm2 | 2.27-3ubuntu1.6+esm2 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2024-05-02·CVSS 9.8
CVE-2024-2961 [CRITICAL] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in GNU C Library.
It was discovered that GNU C Library incorrectly handled netgroup requests.
An attacker could possibly use this issue to cause a crash or execute arbitrary code.
This issue only affected Ubuntu 14.04 LTS. (CVE-2014-9984)
It was discovered that GNU C Library might allow context-dependent
attackers to cause a denial of service. This issue only affected Ubuntu 14.04 LTS.
(CVE-2015-20109)
It was discovered that GNU C Library when processing very long pathname arguments to
the realpath function, could encounter an integer overflow on 32-bit
architectures, leading to a stack-based buffer overflow and, potentially,
arbitrary code execution. This issue only affected Ubuntu 14.04 LTS.
(CVE-2018-11
Red Hat
glibc: buffer overflow (read past end of buffer) in internal_fnmatch=>end_pattern with "**(!()" pattern
vendor_redhat·2023-06-25·CVSS 5.5
CVE-2015-20109 [MEDIUM] CWE-404 glibc: buffer overflow (read past end of buffer) in internal_fnmatch=>end_pattern with "**(!()" pattern
glibc: buffer overflow (read past end of buffer) in internal_fnmatch=>end_pattern with "**(!()" pattern
end_pattern (called from internal_fnmatch) in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent attackers to cause a denial of service (application crash), as demonstrated by use of the fnmatch library function with the **(!() pattern. NOTE: this is not the same as CVE-2015-8984; also, some Linux distributions have fixed CVE-2015-8984 but have not fixed this additional fnmatch issue.
A vulnerability was found in the GNU C Library (glibc). The end_pattern (called from internal_fnmatch) might allow context-dependent attackers to cause a denial of service (application crash), as demonstrated by the use of the fnmatch library function with the **(!() pattern.
Debian
CVE-2015-20109: glibc - end_pattern (called from internal_fnmatch) in the GNU C Library (aka glibc or li...
vendor_debian·2015·CVSS 5.5
CVE-2015-20109 [MEDIUM] CVE-2015-20109: glibc - end_pattern (called from internal_fnmatch) in the GNU C Library (aka glibc or li...
end_pattern (called from internal_fnmatch) in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent attackers to cause a denial of service (application crash), as demonstrated by use of the fnmatch library function with the **(!() pattern. NOTE: this is not the same as CVE-2015-8984; also, some Linux distributions have fixed CVE-2015-8984 but have not fixed this additional fnmatch issue.
Scope: local
bookworm: resolved (fixed in 2.22-1)
bullseye: resolved (fixed in 2.22-1)
forky: resolved (fixed in 2.22-1)
sid: resolved (fixed in 2.22-1)
trixie: resolved (fixed in 2.22-1)
OSV
eglibc, glibc vulnerabilities
osv·2024-05-02·CVSS 9.8
CVE-2014-9984 [CRITICAL] eglibc, glibc vulnerabilities
eglibc, glibc vulnerabilities
It was discovered that GNU C Library incorrectly handled netgroup requests.
An attacker could possibly use this issue to cause a crash or execute arbitrary code.
This issue only affected Ubuntu 14.04 LTS. (CVE-2014-9984)
It was discovered that GNU C Library might allow context-dependent
attackers to cause a denial of service. This issue only affected Ubuntu 14.04 LTS.
(CVE-2015-20109)
It was discovered that GNU C Library when processing very long pathname arguments to
the realpath function, could encounter an integer overflow on 32-bit
architectures, leading to a stack-based buffer overflow and, potentially,
arbitrary code execution. This issue only affected Ubuntu 14.04 LTS.
(CVE-2018-11236)
It was discovered that the GNU C library getcwd function incorre
GHSA
GHSA-rf48-x9gm-3vx2: end_pattern (called from internal_fnmatch) in the GNU C Library (aka glibc or libc6) before 2
ghsa_unreviewed·2023-06-25·CVSS 5.9
CVE-2015-20109 [MEDIUM] CWE-120 GHSA-rf48-x9gm-3vx2: end_pattern (called from internal_fnmatch) in the GNU C Library (aka glibc or libc6) before 2
end_pattern (called from internal_fnmatch) in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent attackers to cause a denial of service (application crash), as demonstrated by use of the fnmatch library function with the **(!() pattern. NOTE: this is not the same as CVE-2015-8984; also, some Linux distributions have fixed CVE-2015-8984 but have not fixed this additional fnmatch issue.
OSV
CVE-2015-20109: end_pattern (called from internal_fnmatch) in the GNU C Library (aka glibc or libc6) before 2
osv·2023-06-25·CVSS 5.5
CVE-2015-20109 [MEDIUM] CVE-2015-20109: end_pattern (called from internal_fnmatch) in the GNU C Library (aka glibc or libc6) before 2
end_pattern (called from internal_fnmatch) in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent attackers to cause a denial of service (application crash), as demonstrated by use of the fnmatch library function with the **(!() pattern. NOTE: this is not the same as CVE-2015-8984; also, some Linux distributions have fixed CVE-2015-8984 but have not fixed this additional fnmatch issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-06-25
Published