CVE-2017-15671
published 2017-10-20CVE-2017-15671: The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27, when invoked with GLOB_TILDE, could skip freeing allocated memory when…
PriorityP423medium5.9CVSS 3.0
AVNACHPRNUINSUCNINAH
EPSS
1.43%
70.3th percentile
The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27, when invoked with GLOB_TILDE, could skip freeing allocated memory when processing the ~ operator with a long user name, potentially leading to a denial of service (memory leak).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.25-3 (bookworm) | glibc 2.25-3 (bookworm) |
| gnu | glibc | <= 2.26 | — |
| gnu | glibc | >= 0 < 2.25-3 | 2.25-3 |
| gnu | glibc | >= 0 < 2.25-3 | 2.25-3 |
| gnu | glibc | >= 0 < 2.25-3 | 2.25-3 |
| gnu | glibc | >= 0 < 2.25-3 | 2.25-3 |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.9MEDIUM
vendor_debian5.9LOW
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3gv3-62jc-35qm: The glob function in glob
ghsa_unreviewed·2022-05-13
CVE-2017-15671 [MEDIUM] CWE-772 GHSA-3gv3-62jc-35qm: The glob function in glob
The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27, when invoked with GLOB_TILDE, could skip freeing allocated memory when processing the ~ operator with a long user name, potentially leading to a denial of service (memory leak).
OSV
CVE-2017-15671: The glob function in glob
osv·2017-10-20·CVSS 5.9
CVE-2017-15671 [MEDIUM] CVE-2017-15671: The glob function in glob
The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27, when invoked with GLOB_TILDE, could skip freeing allocated memory when processing the ~ operator with a long user name, potentially leading to a denial of service (memory leak).
Red Hat
glibc: Memory leak in glob with GLOB_TILDE
vendor_redhat·2017-10-20·CVSS 5.9
CVE-2017-15671 [MEDIUM] CWE-400 glibc: Memory leak in glob with GLOB_TILDE
glibc: Memory leak in glob with GLOB_TILDE
The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27, when invoked with GLOB_TILDE, could skip freeing allocated memory when processing the ~ operator with a long user name, potentially leading to a denial of service (memory leak).
Package: compat-glibc (Red Hat Enterprise Linux 5) - Will not fix
Package: glibc (Red Hat Enterprise Linux 5) - Will not fix
Package: compat-glibc (Red Hat Enterprise Linux 6) - Will not fix
Package: glibc (Red Hat Enterprise Linux 6) - Will not fix
Package: compat-glibc (Red Hat Enterprise Linux 7) - Will not fix
Package: glibc (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2017-15671: glibc - The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.2...
vendor_debian·2017·CVSS 5.9
CVE-2017-15671 [MEDIUM] CVE-2017-15671: glibc - The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.2...
The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27, when invoked with GLOB_TILDE, could skip freeing allocated memory when processing the ~ operator with a long user name, potentially leading to a denial of service (memory leak).
Scope: local
bookworm: resolved (fixed in 2.25-3)
bullseye: resolved (fixed in 2.25-3)
forky: resolved (fixed in 2.25-3)
sid: resolved (fixed in 2.25-3)
trixie: resolved (fixed in 2.25-3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-15671 glibc: Memory leak in glob with GLOB_TILDE
bugzilla·2017-10-20·CVSS 5.9
CVE-2017-15671 [MEDIUM] CVE-2017-15671 glibc: Memory leak in glob with GLOB_TILDE
CVE-2017-15671 glibc: Memory leak in glob with GLOB_TILDE
A memory leak was found in glibc. An attacker might use this to cause a denial-of-service (heap exhaustion).
Upstream issue:
https://sourceware.org/bugzilla/show_bug.cgi?id=22325
Discussion:
Created glibc tracking bugs for this issue:
Affects: fedora-all [bug 1504807]
Bugzilla
CVE-2017-15670 CVE-2017-15671 glibc: various flaws [fedora-all]
bugzilla·2017-10-20·CVSS 9.8
CVE-2017-15670 [CRITICAL] CVE-2017-15670 CVE-2017-15671 glibc: various flaws [fedora-all]
CVE-2017-15670 CVE-2017-15671 glibc: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Wh
2017-10-20
Published