CVE-2015-8983Integer Overflow or Wraparound in Glibc

Severity
8.1HIGHNVD
EPSS
0.5%
top 32.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 20
Latest updateMay 17

Description

Integer overflow in the _IO_wstr_overflow function in libio/wstrops.c in the GNU C Library (aka glibc or libc6) before 2.22 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors related to computing a size in bytes, which triggers a heap-based buffer overflow.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages2 packages

Debiangnu/glibc< 2.21-1+3
NVDgnu/glibc2.21

Patches

🔴Vulnerability Details

4
GHSA
GHSA-77qx-ffg2-4jrv: Integer overflow in the _IO_wstr_overflow function in libio/wstrops2022-05-17
OSV
eglibc, glibc vulnerabilities2017-03-21
CVEList
CVE-2015-8983: Integer overflow in the _IO_wstr_overflow function in libio/wstrops2017-03-20
OSV
CVE-2015-8983: Integer overflow in the _IO_wstr_overflow function in libio/wstrops2017-03-20

📋Vendor Advisories

3
Ubuntu
GNU C Library vulnerabilities2017-03-21
Red Hat
glibc: _IO_wstr_overflow integer overflow2015-02-22
Debian
CVE-2015-8983: glibc - Integer overflow in the _IO_wstr_overflow function in libio/wstrops.c in the GNU...2015

💬Community

2
Bugzilla
CVE-2015-8983 glibc: _IO_wstr_overflow integer overflow [fedora-all]2015-02-24
Bugzilla
CVE-2015-8983 glibc: _IO_wstr_overflow integer overflow2015-02-24
CVE-2015-8983 — Integer Overflow or Wraparound in Glibc | cvebase