CVE-2015-5277
published 2015-12-17CVE-2015-5277: The get_contents function in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) before 2.20 might allow local users…
PriorityP428high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.59%
44.6th percentile
The get_contents function in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) before 2.20 might allow local users to cause a denial of service (heap corruption) or gain privileges via a long line in the NSS files database.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | glibc | < glibc 2.21-1 (bookworm) | glibc 2.21-1 (bookworm) |
| eglibc | eglibc | >= 0 < 2.19-0ubuntu6.8 | 2.19-0ubuntu6.8 |
| eglibc | eglibc | >= 0 < 2.19-0ubuntu6.9 | 2.19-0ubuntu6.9 |
| gnu | glibc | <= 2.19 | — |
| gnu | glibc | >= 0 < 2.21-1 | 2.21-1 |
| gnu | glibc | >= 0 < 2.21-1 | 2.21-1 |
| gnu | glibc | >= 0 < 2.21-1 | 2.21-1 |
| gnu | glibc | >= 0 < 2.21-1 | 2.21-1 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
vendor_ubuntu2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hjm6-jvmc-534p: The get_contents function in nss_files/files-XXX
ghsa_unreviewed·2022-05-17
CVE-2015-5277 [HIGH] CWE-119 GHSA-hjm6-jvmc-534p: The get_contents function in nss_files/files-XXX
The get_contents function in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) before 2.20 might allow local users to cause a denial of service (heap corruption) or gain privileges via a long line in the NSS files database.
OSV
eglibc, glibc regression
osv·2016-05-26·CVSS 2.6
CVE-2014-9761 [LOW] eglibc, glibc regression
eglibc, glibc regression
USN-2985-1 fixed vulnerabilities in the GNU C Library. The fix for
CVE-2014-9761 introduced a regression which affected applications that
use the libm library but were not fully restarted after the upgrade.
This update removes the fix for CVE-2014-9761 and a future update
will be provided to address this issue.
We apologize for the inconvenience.
Original advisory details:
Martin Carpenter discovered that pt_chown in the GNU C Library did not
properly check permissions for tty files. A local attacker could use this
to gain administrative privileges or expose sensitive information.
(CVE-2013-2207, CVE-2016-2856)
Robin Hack discovered that the Name Service Switch (NSS) implementation in
the GNU C Library did not properly manage its file descriptors. An attacker
OSV
eglibc, glibc vulnerabilities
osv·2016-05-25·CVSS 2.6
CVE-2013-2207 [LOW] eglibc, glibc vulnerabilities
eglibc, glibc vulnerabilities
Martin Carpenter discovered that pt_chown in the GNU C Library did not
properly check permissions for tty files. A local attacker could use this
to gain administrative privileges or expose sensitive information.
(CVE-2013-2207, CVE-2016-2856)
Robin Hack discovered that the Name Service Switch (NSS) implementation in
the GNU C Library did not properly manage its file descriptors. An attacker
could use this to cause a denial of service (infinite loop).
(CVE-2014-8121)
Joseph Myers discovered that the GNU C Library did not properly handle long
arguments to functions returning a representation of Not a Number (NaN). An
attacker could use this to cause a denial of service (stack exhaustion
leading to an application crash) or possibly execute arbitrary code.
(CVE
OSV
CVE-2015-5277: The get_contents function in nss_files/files-XXX
osv·2015-12-17·CVSS 7.2
CVE-2015-5277 [HIGH] CVE-2015-5277: The get_contents function in nss_files/files-XXX
The get_contents function in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) before 2.20 might allow local users to cause a denial of service (heap corruption) or gain privileges via a long line in the NSS files database.
Ubuntu
GNU C Library regression
vendor_ubuntu·2016-05-26·CVSS 2.6
CVE-2014-9761 [LOW] GNU C Library regression
Title: GNU C Library regression
Summary: USN-2985-1 introduced a regression in the GNU C Library.
USN-2985-1 fixed vulnerabilities in the GNU C Library. The fix for
CVE-2014-9761 introduced a regression which affected applications that
use the libm library but were not fully restarted after the upgrade.
This update removes the fix for CVE-2014-9761 and a future update
will be provided to address this issue.
We apologize for the inconvenience.
Original advisory details:
Martin Carpenter discovered that pt_chown in the GNU C Library did not
properly check permissions for tty files. A local attacker could use this
to gain administrative privileges or expose sensitive information.
(CVE-2013-2207, CVE-2016-2856)
Robin Hack discovered that the Name Service Switch (NSS) implementation in
th
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2016-05-25·CVSS 2.6
CVE-2013-2207 [LOW] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in the GNU C Library.
Martin Carpenter discovered that pt_chown in the GNU C Library did not
properly check permissions for tty files. A local attacker could use this
to gain administrative privileges or expose sensitive information.
(CVE-2013-2207, CVE-2016-2856)
Robin Hack discovered that the Name Service Switch (NSS) implementation in
the GNU C Library did not properly manage its file descriptors. An attacker
could use this to cause a denial of service (infinite loop).
(CVE-2014-8121)
Joseph Myers discovered that the GNU C Library did not properly handle long
arguments to functions returning a representation of Not a Number (NaN). An
attacker could use this to cause a denial of service (stack exhaustion
Red Hat
glibc: data corruption while reading the NSS files database
vendor_redhat·2015-09-14·CVSS 7.2
CVE-2015-5277 [HIGH] CWE-119 glibc: data corruption while reading the NSS files database
glibc: data corruption while reading the NSS files database
The get_contents function in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) before 2.20 might allow local users to cause a denial of service (heap corruption) or gain privileges via a long line in the NSS files database.
It was discovered that the nss_files backend for the Name Service Switch in glibc would return incorrect data to applications or corrupt the heap (depending on adjacent heap contents). A local attacker could potentially use this flaw to execute arbitrary code on the system.
Package: glibc (Red Hat Enterprise Linux 5) - Not affected
Package: glibc (Red Hat Enterprise Linux 6) - Not affected
Red Hat
docker: regression of CVE-2014-5277
vendor_redhat·2015-03-27·CVSS 5.0
CVE-2015-1843 [MEDIUM] CWE-300 docker: regression of CVE-2014-5277
docker: regression of CVE-2014-5277
The Red Hat docker package before 1.5.0-28, when using the --add-registry option, falls back to HTTP when the HTTPS connection to the registry fails, which allows man-in-the-middle attackers to conduct downgrade attacks and obtain authentication and image data by leveraging a network position between the client and the registry to block HTTPS traffic. NOTE: this vulnerability exists because of a CVE-2014-5277 regression.
It was found that the fix for the CVE-2014-5277 issue was incomplete: the docker client could under certain circumstances erroneously fall back to HTTP when an HTTPS connection to a registry failed. This could allow a man-in-the-middle attacker to obtain authentication and image data from traffic sent from a client to the registry.
Debian
CVE-2015-5277: glibc - The get_contents function in nss_files/files-XXX.c in the Name Service Switch (N...
vendor_debian·2015·CVSS 7.2
CVE-2015-5277 [HIGH] CVE-2015-5277: glibc - The get_contents function in nss_files/files-XXX.c in the Name Service Switch (N...
The get_contents function in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) before 2.20 might allow local users to cause a denial of service (heap corruption) or gain privileges via a long line in the NSS files database.
Scope: local
bookworm: resolved (fixed in 2.21-1)
bullseye: resolved (fixed in 2.21-1)
forky: resolved (fixed in 2.21-1)
sid: resolved (fixed in 2.21-1)
trixie: resolved (fixed in 2.21-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5277 glibc: data corruption while reading the NSS files database
bugzilla·2015-09-14·CVSS 7.2
CVE-2015-5277 [HIGH] CVE-2015-5277 glibc: data corruption while reading the NSS files database
CVE-2015-5277 glibc: data corruption while reading the NSS files database
It was discovered that the nss_files backend for the Name Service Switch in glibc would return incorrect data to applications or corrupt the heap (depending on adjacent heap contents), potentially resulting in arbitrary code execution.
Discussion:
External references:
https://sourceware.org/bugzilla/show_bug.cgi?id=17079
---
Upstream commit:
https://sourceware.org/git/gitweb.cgi?p=glibc.git;a=commitdiff;h=ac60763eac3d43b7234dd21286ad3ec3f17957fc
---
Acknowledgements:
This issue was discovered by Sumit Bose and Lukáš Slebodník of Red Hat.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2015:2172 https://rhn.redhat.com/errata/RHSA-2015-2172.html
---
This
Bugzilla
CVE-2015-5277 glibc: nss_files doesn't detect ERANGE problems correctly [rhel-7.3]
bugzilla·2014-05-19·CVSS 7.2
CVE-2015-5277 [HIGH] CVE-2015-5277 glibc: nss_files doesn't detect ERANGE problems correctly [rhel-7.3]
CVE-2015-5277 glibc: nss_files doesn't detect ERANGE problems correctly [rhel-7.3]
Created attachment 897322
Test program, takes optional user name ("root") and initial buffer size (4) as arguments
Description of problem:
In glibc-2.17-c758a686/nss/nss_files/files-XXX.c, in get_contents(), the loop appears to be checking for a too-small passed-in buffer incorrectly, in that it assigns 0xff to the final byte in the buffer after passing the buffer to fgets_unlocked instead of before.
Version-Release number of selected component (if applicable):
glibc-2.17-55.el7.x86_64
How reproducible:
Always
Steps to Reproduce:
1. Call getpwnam_r() with bufsize set to a small number (4 in my test).
Actual results:
getpwnam_r() returns 0
Expected results:
getpwnam_r() returns ERANGE
Discussion:
Thi
http://packetstormsecurity.com/files/154361/Cisco-Device-Hardcoded-Credentials-GNU-glibc-BusyBox.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2172.htmlhttp://seclists.org/fulldisclosure/2019/Sep/7http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/78092http://www.securitytracker.com/id/1034196http://www.ubuntu.com/usn/USN-2985-1http://www.ubuntu.com/usn/USN-2985-2https://bugzilla.redhat.com/show_bug.cgi?id=1262914https://seclists.org/bugtraq/2019/Sep/7https://security.gentoo.org/glsa/201702-11https://sourceware.org/bugzilla/show_bug.cgi?id=17079https://sourceware.org/ml/libc-alpha/2014-09/msg00088.htmlhttp://packetstormsecurity.com/files/154361/Cisco-Device-Hardcoded-Credentials-GNU-glibc-BusyBox.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2172.htmlhttp://seclists.org/fulldisclosure/2019/Sep/7http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/78092http://www.securitytracker.com/id/1034196http://www.ubuntu.com/usn/USN-2985-1http://www.ubuntu.com/usn/USN-2985-2https://bugzilla.redhat.com/show_bug.cgi?id=1262914https://seclists.org/bugtraq/2019/Sep/7https://security.gentoo.org/glsa/201702-11https://sourceware.org/bugzilla/show_bug.cgi?id=17079https://sourceware.org/ml/libc-alpha/2014-09/msg00088.html
2015-12-17
Published