CVE-2009-5155
26.02.2019, 02:29
In the GNU C Library (aka glibc or libc6) before 2.28, parse_reg_exp in posix/regcomp.c misparses alternatives, which allows attackers to cause a denial of service (assertion failure and application exit) or trigger an incorrect result by attempting a regular-expression match.Enginsight
| Vendor | Product | Version |
|---|---|---|
| gnu | glibc | 𝑥 < 2.28 |
| netapp | cloud_backup | * |
| netapp | ontap_select_deploy_administration_utility | - |
| netapp | steelstore_cloud_integrated_storage | - |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| glibc |
| ||||||||||||||||
| gnulib |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| eglibc |
| ||||||||||||||||||||||||||||||
| glibc |
| ||||||||||||||||||||||||||||||
| gnulib |
|
Common Weakness Enumeration
References