CVE-2017-15804
published 2017-10-22CVE-2017-15804: The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27 contains a buffer overflow during unescaping of user names with the ~…
PriorityP344critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
2.80%
85.0th percentile
The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27 contains a buffer overflow during unescaping of user names with the ~ operator.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.25-3 (bookworm) | glibc 2.25-3 (bookworm) |
| eglibc | eglibc | >= 0 < 2.19-0ubuntu6.14 | 2.19-0ubuntu6.14 |
| gnu | glibc | <= 2.26 | — |
| gnu | glibc | >= 0 < 2.25-3 | 2.25-3 |
| gnu | glibc | >= 0 < 2.25-3 | 2.25-3 |
| gnu | glibc | >= 0 < 2.25-3 | 2.25-3 |
| gnu | glibc | >= 0 < 2.25-3 | 2.25-3 |
| gnu | glibc | >= 0 < 2.23-0ubuntu10 | 2.23-0ubuntu10 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3r84-39rf-qwh3: The glob function in glob
ghsa_unreviewed·2022-05-14
CVE-2017-15804 [CRITICAL] CWE-119 GHSA-3r84-39rf-qwh3: The glob function in glob
The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27 contains a buffer overflow during unescaping of user names with the ~ operator.
OSV
eglibc, glibc vulnerabilities
osv·2018-01-17·CVSS 7.8
CVE-2018-1000001 [HIGH] eglibc, glibc vulnerabilities
eglibc, glibc vulnerabilities
It was discovered that the GNU C library did not properly handle all of
the possible return values from the kernel getcwd(2) syscall. A local
attacker could potentially exploit this to execute arbitrary code in setuid
programs and gain administrative privileges. (CVE-2018-1000001)
A memory leak was discovered in the _dl_init_paths() function in the GNU
C library dynamic loader. A local attacker could potentially exploit this
with a specially crafted value in the LD_HWCAP_MASK environment variable,
in combination with CVE-2017-1000409 and another vulnerability on a system
with hardlink protections disabled, in order to gain administrative
privileges. (CVE-2017-1000408)
A heap-based buffer overflow was discovered in the _dl_init_paths()
function in the GNU C
OSV
CVE-2017-15804: The glob function in glob
osv·2017-10-22·CVSS 9.8
CVE-2017-15804 [CRITICAL] CVE-2017-15804: The glob function in glob
The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27 contains a buffer overflow during unescaping of user names with the ~ operator.
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2018-01-17·CVSS 7.8
CVE-2017-1000408 [HIGH] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in the GNU C library.
It was discovered that the GNU C library did not properly handle all of
the possible return values from the kernel getcwd(2) syscall. A local
attacker could potentially exploit this to execute arbitrary code in setuid
programs and gain administrative privileges. (CVE-2018-1000001)
A memory leak was discovered in the _dl_init_paths() function in the GNU
C library dynamic loader. A local attacker could potentially exploit this
with a specially crafted value in the LD_HWCAP_MASK environment variable,
in combination with CVE-2017-1000409 and another vulnerability on a system
with hardlink protections disabled, in order to gain administrative
privileges. (CVE-2017-1000408)
A heap-based buf
Red Hat
glibc: Buffer overflow during unescaping of user names with the ~ operator
vendor_redhat·2017-10-21·CVSS 9.8
CVE-2017-15804 [CRITICAL] CWE-122 glibc: Buffer overflow during unescaping of user names with the ~ operator
glibc: Buffer overflow during unescaping of user names with the ~ operator
The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27 contains a buffer overflow during unescaping of user names with the ~ operator.
Package: compat-glibc (Red Hat Enterprise Linux 5) - Not affected
Package: glibc (Red Hat Enterprise Linux 5) - Not affected
Package: compat-glibc (Red Hat Enterprise Linux 6) - Not affected
Package: compat-glibc (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2017-15804: glibc - The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.2...
vendor_debian·2017·CVSS 9.8
CVE-2017-15804 [CRITICAL] CVE-2017-15804: glibc - The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.2...
The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27 contains a buffer overflow during unescaping of user names with the ~ operator.
Scope: local
bookworm: resolved (fixed in 2.25-3)
bullseye: resolved (fixed in 2.25-3)
forky: resolved (fixed in 2.25-3)
sid: resolved (fixed in 2.25-3)
trixie: resolved (fixed in 2.25-3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-15804 glibc: Buffer overflow during unescaping of user names with the ~ operator
bugzilla·2017-10-23·CVSS 9.8
CVE-2017-15804 [CRITICAL] CVE-2017-15804 glibc: Buffer overflow during unescaping of user names with the ~ operator
CVE-2017-15804 glibc: Buffer overflow during unescaping of user names with the ~ operator
The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27 contains a buffer overflow during unescaping of user names with the ~ operator.
Upstream issue:
https://sourceware.org/bugzilla/show_bug.cgi?id=22332
Upstream patch:
https://sourceware.org/git/gitweb.cgi?p=glibc.git;a=commit;h=a159b53fa059947cc2548e3b0d5bdcf7b9630ba8
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:0805 https://access.redhat.com/errata/RHSA-2018:0805
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:1879 https://access.redhat.com/errata/RHSA-2018:1879
CTF
Baby_glob / README
ctf_writeups·2021·CVSS 9.8
CVE-2017-15804 [CRITICAL] Baby_glob / README
# Baby Glob
### Challenge Description
Super secure path finder from your own 2017.
#### md5sum
chall - `60aedc6cf9a7b163254cfc2ffea64c04`
**Challenge Files**
+ [glob](./Handout/Handout.zip)
### Short Writeup
The glob function used is vulnerable to [CVE-2017-15804](https://sourceware.org/git/?p=glibc.git;a=blobdiff;f=posix/glob.c;h=cb39779d0716d430b0580d2493f56e38f832cb79;hp=15a6c0cf13bdccb7972183884f87c5d4be2a2f1b;hb=a159b53fa059947cc2548e3b0d5bdcf7b9630ba8;hpb=914c9994d27b80bc3b71c483e801a4f04e269ba6) which is basically a heap overflow caused during improper `GLOB_TILDE` unescaping.
### Author
Cyb0rG
### Flag
`inctf{CVE-2017-15804_Subtl3_H3ap_Overfl0w}`
### Writeup
+ [blog.bi0s.in](https://blog.bi0s.in/2021/08/17/Pwn/InCTFi21-Baby_Glob/)
http://www.securityfocus.com/bid/101535https://access.redhat.com/errata/RHSA-2018:0805https://access.redhat.com/errata/RHSA-2018:1879https://sourceware.org/bugzilla/show_bug.cgi?id=22332https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commit%3Bh=a159b53fa059947cc2548e3b0d5bdcf7b9630ba8http://www.securityfocus.com/bid/101535https://access.redhat.com/errata/RHSA-2018:0805https://access.redhat.com/errata/RHSA-2018:1879https://sourceware.org/bugzilla/show_bug.cgi?id=22332https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commit%3Bh=a159b53fa059947cc2548e3b0d5bdcf7b9630ba8
2017-10-22
Published