CVE-2015-8776
published 2016-04-19CVE-2015-8776: The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash)…
PriorityP338critical9.1CVSS 3.0
AVNACLPRNUINSUCHINAH
EPSS
4.61%
90.7th percentile
The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range time value.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | glibc | < glibc 2.21-7 (bookworm) | glibc 2.21-7 (bookworm) |
| eglibc | eglibc | >= 0 < 2.19-0ubuntu6.8 | 2.19-0ubuntu6.8 |
| eglibc | eglibc | >= 0 < 2.19-0ubuntu6.9 | 2.19-0ubuntu6.9 |
| fedoraproject | fedora | — | — |
| gnu | glibc | <= 2.22 | — |
| gnu | glibc | >= 0 < 2.21-7 | 2.21-7 |
| gnu | glibc | >= 0 < 2.21-7 | 2.21-7 |
| gnu | glibc | >= 0 < 2.21-7 | 2.21-7 |
| gnu | glibc | >= 0 < 2.21-7 | 2.21-7 |
| opensuse | opensuse | — | — |
| suse | linux_enterprise_debuginfo | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
| suse | suse_linux_enterprise_server | — | — |
CVSS provenance
nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
osv9.1CRITICAL
vendor_debian9.1CRITICAL
vendor_redhat9.1CRITICAL
vendor_ubuntu2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mm79-9vr7-wx53: The strftime function in the GNU C Library (aka glibc or libc6) before 2
ghsa_unreviewed·2022-05-14
CVE-2015-8776 [CRITICAL] GHSA-mm79-9vr7-wx53: The strftime function in the GNU C Library (aka glibc or libc6) before 2
The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range time value.
OSV
eglibc, glibc regression
osv·2016-05-26·CVSS 2.6
CVE-2014-9761 [LOW] eglibc, glibc regression
eglibc, glibc regression
USN-2985-1 fixed vulnerabilities in the GNU C Library. The fix for
CVE-2014-9761 introduced a regression which affected applications that
use the libm library but were not fully restarted after the upgrade.
This update removes the fix for CVE-2014-9761 and a future update
will be provided to address this issue.
We apologize for the inconvenience.
Original advisory details:
Martin Carpenter discovered that pt_chown in the GNU C Library did not
properly check permissions for tty files. A local attacker could use this
to gain administrative privileges or expose sensitive information.
(CVE-2013-2207, CVE-2016-2856)
Robin Hack discovered that the Name Service Switch (NSS) implementation in
the GNU C Library did not properly manage its file descriptors. An attacker
OSV
eglibc, glibc vulnerabilities
osv·2016-05-25·CVSS 2.6
CVE-2013-2207 [LOW] eglibc, glibc vulnerabilities
eglibc, glibc vulnerabilities
Martin Carpenter discovered that pt_chown in the GNU C Library did not
properly check permissions for tty files. A local attacker could use this
to gain administrative privileges or expose sensitive information.
(CVE-2013-2207, CVE-2016-2856)
Robin Hack discovered that the Name Service Switch (NSS) implementation in
the GNU C Library did not properly manage its file descriptors. An attacker
could use this to cause a denial of service (infinite loop).
(CVE-2014-8121)
Joseph Myers discovered that the GNU C Library did not properly handle long
arguments to functions returning a representation of Not a Number (NaN). An
attacker could use this to cause a denial of service (stack exhaustion
leading to an application crash) or possibly execute arbitrary code.
(CVE
OSV
CVE-2015-8776: The strftime function in the GNU C Library (aka glibc or libc6) before 2
osv·2016-04-19·CVSS 9.1
CVE-2015-8776 [CRITICAL] CVE-2015-8776: The strftime function in the GNU C Library (aka glibc or libc6) before 2
The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range time value.
Ubuntu
GNU C Library regression
vendor_ubuntu·2016-05-26·CVSS 2.6
CVE-2014-9761 [LOW] GNU C Library regression
Title: GNU C Library regression
Summary: USN-2985-1 introduced a regression in the GNU C Library.
USN-2985-1 fixed vulnerabilities in the GNU C Library. The fix for
CVE-2014-9761 introduced a regression which affected applications that
use the libm library but were not fully restarted after the upgrade.
This update removes the fix for CVE-2014-9761 and a future update
will be provided to address this issue.
We apologize for the inconvenience.
Original advisory details:
Martin Carpenter discovered that pt_chown in the GNU C Library did not
properly check permissions for tty files. A local attacker could use this
to gain administrative privileges or expose sensitive information.
(CVE-2013-2207, CVE-2016-2856)
Robin Hack discovered that the Name Service Switch (NSS) implementation in
th
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2016-05-25·CVSS 2.6
CVE-2013-2207 [LOW] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in the GNU C Library.
Martin Carpenter discovered that pt_chown in the GNU C Library did not
properly check permissions for tty files. A local attacker could use this
to gain administrative privileges or expose sensitive information.
(CVE-2013-2207, CVE-2016-2856)
Robin Hack discovered that the Name Service Switch (NSS) implementation in
the GNU C Library did not properly manage its file descriptors. An attacker
could use this to cause a denial of service (infinite loop).
(CVE-2014-8121)
Joseph Myers discovered that the GNU C Library did not properly handle long
arguments to functions returning a representation of Not a Number (NaN). An
attacker could use this to cause a denial of service (stack exhaustion
Red Hat
glibc: Segmentation fault caused by passing out-of-range data to strftime()
vendor_redhat·2015-09-20·CVSS 9.1
CVE-2015-8776 [CRITICAL] glibc: Segmentation fault caused by passing out-of-range data to strftime()
glibc: Segmentation fault caused by passing out-of-range data to strftime()
The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range time value.
It was found that out-of-range time values passed to the strftime() function could result in an out-of-bounds memory access. This could lead to application crash or, potentially, information disclosure.
Mitigation: Check time values before they are passed to strftime, or call strftime only with struct tm values computed by gmtime or localtime.
Package: compat-glibc (Red Hat Enterprise Linux 5) - Will not fix
Package: glibc (Red Hat Enterprise Linux 5) - Will not fix
Package: compa
Debian
CVE-2015-8776: glibc - The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allo...
vendor_debian·2015·CVSS 9.1
CVE-2015-8776 [CRITICAL] CVE-2015-8776: glibc - The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allo...
The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range time value.
Scope: local
bookworm: resolved (fixed in 2.21-7)
bullseye: resolved (fixed in 2.21-7)
forky: resolved (fixed in 2.21-7)
sid: resolved (fixed in 2.21-7)
trixie: resolved (fixed in 2.21-7)
No detection rules found.
No public exploits indexed.
arXiv
Fuzzing BusyBox: Leveraging LLM and Crash Reuse for Embedded Bug Unearthing
arxiv_fulltext·2024-03-06
Fuzzing BusyBox: Leveraging LLM and Crash Reuse for Embedded Bug Unearthing
Fuzzing BusyBox: Leveraging LLM and Crash Reuse for Embedded Bug Unearthing
Asmita^1, Yaroslav Oliinyk^2, Michael Scott^2, Ryan Tsang^1,
Chongzhou Fang^1, Houman Homayoun^1
^1University of California, Davis
^2NetRise
## Abstract
BusyBox, an open-source software bundling over 300 essential Linux commands into a single executable, is ubiquitous in Linux-based embedded devices. Vulnerabilities in BusyBox can have far-reaching consequences, affecting a wide array of devices. This research, driven by the extensive use of BusyBox, delved into its analysis. The study revealed the prevalence of older BusyBox versions in real-world embedded products, prompting us to conduct fuzz testing on BusyBox. Fuzzing, a pivotal software testing method, aims to induce crashes that are subsequently scrutini
Bugzilla
CVE-2015-8776 glibc: Segmentation fault caused by passing out-of-range data to strftime()
bugzilla·2016-01-20·CVSS 9.1
CVE-2015-8776 [CRITICAL] CVE-2015-8776 glibc: Segmentation fault caused by passing out-of-range data to strftime()
CVE-2015-8776 glibc: Segmentation fault caused by passing out-of-range data to strftime()
It was found that out-of-range time values passed to the strftime function may cause it to crash, leading to a denial of service, or potentially disclosure information.
Upstream bug:
https://sourceware.org/bugzilla/show_bug.cgi?id=18985
CVE assignment:
http://seclists.org/oss-sec/2016/q1/153
Discussion:
Created glibc tracking bugs for this issue:
Affects: fedora-all [bug 1300300]
---
Upstream commit at:
https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=d36c75fc0d44deec29635dd239b0fbd206ca49b7
---
Public reproducer available at:
https://sourceware.org/git/gitweb.cgi?p=glibc.git;a=blob_plain;f=time/tst-strftime.c;h=af3ff72faf9588126fb269b0e9080357c32b5fcb;hb=d36c75fc0d44deec29635dd239b0f
Bugzilla
CVE-2015-8776 glibc: Segmentation fault caused by passing out-of-range data to strftime() [fedora-all]
bugzilla·2016-01-20·CVSS 9.1
CVE-2015-8776 [CRITICAL] CVE-2015-8776 glibc: Segmentation fault caused by passing out-of-range data to strftime() [fedora-all]
CVE-2015-8776 glibc: Segmentation fault caused by passing out-of-range data to strftime() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multip
http://lists.fedoraproject.org/pipermail/package-announce/2016-May/184626.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00036.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00037.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00038.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00039.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00042.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0680.htmlhttp://www.debian.org/security/2016/dsa-3480http://www.debian.org/security/2016/dsa-3481http://www.openwall.com/lists/oss-security/2016/01/19/11http://www.openwall.com/lists/oss-security/2016/01/20/1http://www.securityfocus.com/bid/83277http://www.ubuntu.com/usn/USN-2985-1http://www.ubuntu.com/usn/USN-2985-2https://access.redhat.com/errata/RHSA-2017:1916https://security.gentoo.org/glsa/201602-02https://security.gentoo.org/glsa/201702-11https://sourceware.org/bugzilla/show_bug.cgi?id=18985https://www.sourceware.org/ml/libc-alpha/2016-02/msg00502.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-May/184626.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00036.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00037.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00038.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00039.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00042.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0680.htmlhttp://www.debian.org/security/2016/dsa-3480http://www.debian.org/security/2016/dsa-3481http://www.openwall.com/lists/oss-security/2016/01/19/11http://www.openwall.com/lists/oss-security/2016/01/20/1http://www.securityfocus.com/bid/83277http://www.ubuntu.com/usn/USN-2985-1http://www.ubuntu.com/usn/USN-2985-2https://access.redhat.com/errata/RHSA-2017:1916https://security.gentoo.org/glsa/201602-02https://security.gentoo.org/glsa/201702-11https://sourceware.org/bugzilla/show_bug.cgi?id=18985https://www.sourceware.org/ml/libc-alpha/2016-02/msg00502.html
2016-04-19
Published