CVE-2015-5229Redhat Enterprise Linux vulnerability

CWE-179 documents6 sources
Severity
7.5HIGHNVD
EPSS
1.0%
top 22.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 8
Latest updateMay 17

Description

The calloc function in the glibc package in Red Hat Enterprise Linux (RHEL) 6.7 and 7.2 does not properly initialize memory areas, which might allow context-dependent attackers to cause a denial of service (hang or crash) via unspecified vectors.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

Also affects: Enterprise Linux 6.7, 7.2

🔴Vulnerability Details

2
GHSA
GHSA-vhfq-hmc6-hfjh: The calloc function in the glibc package in Red Hat Enterprise Linux (RHEL) 62022-05-17
CVEList
CVE-2015-5229: The calloc function in the glibc package in Red Hat Enterprise Linux (RHEL) 62016-04-08

📋Vendor Advisories

2
Red Hat
glibc: calloc may return non-zero memory2015-08-21
Debian
CVE-2015-5229: glibc - The calloc function in the glibc package in Red Hat Enterprise Linux (RHEL) 6.7 ...2015

💬Community

4
Bugzilla
CVE-2015-5229 glibc: calloc() returns non-zero'ed memory2015-12-24
Bugzilla
CVE-2015-5229 glibc: calloc() returns non-zero'ed memory [rhel-7.3.0]2015-12-23
Bugzilla
CVE-2015-5229 glibc: calloc may return non-zero memory2015-08-24
Bugzilla
CVE-2015-5229 glibc: calloc() returns non-zero'ed memory2015-07-25
CVE-2015-5229 — Redhat Enterprise Linux vulnerability | cvebase