CVE-2017-7476

Gnulib before 2017-04-26 has a heap-based buffer overflow with the TZ environment variable. The error is in the save_abbr function in time_rz.c.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 76%
Affected Products (NVD)
VendorProductVersion
gnulibgnulib
𝑥
≤ 2017-04-25
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
gnulib
bookworm
20230209+stable-1
fixed
bullseye
20210102~ebaa53c-1
fixed
sid
20240701-1
fixed
trixie
20240701-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gnulib
artful
ignored
bionic
not-affected
cosmic
not-affected
disco
not-affected
precise
ignored
trusty
dne
xenial
not-affected
yakkety
ignored
zesty
ignored
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
coreutils
suse enterprise desktop 15
8.29-2.12
fixed
suse enterprise desktop 15 SP1
8.29-2.12
fixed
suse enterprise desktop 15 SP2
8.29-2.12
fixed
suse enterprise desktop 15 SP3
8.32-1.2
fixed
suse enterprise desktop 15 SP4
8.32-150400.7.5
fixed
suse enterprise desktop 15 SP5
8.32-150400.7.5
fixed
suse enterprise desktop 15 SP6
8.32-150400.9.3.1
fixed
suse enterprise desktop 15 SP7
8.32-150400.9.6.1
fixed
suse enterprise sap 15
8.29-2.12
fixed
suse enterprise sap 15 SP1
8.29-2.12
fixed
suse enterprise sap 15 SP2
8.29-2.12
fixed
suse enterprise sap 15 SP3
8.32-1.2
fixed
suse enterprise sap 15 SP4
8.32-150400.7.5
fixed
suse enterprise sap 15 SP5
8.32-150400.7.5
fixed
suse enterprise sap 15 SP6
8.32-150400.9.3.1
fixed
suse enterprise sap 15 SP7
8.32-150400.9.6.1
fixed
suse enterprise server 15
8.29-2.12
fixed
suse enterprise server 15 SP1
8.29-2.12
fixed
suse enterprise server 15 SP2
8.29-2.12
fixed
suse enterprise server 15 SP3
8.32-1.2
fixed
suse enterprise server 15 SP4
8.32-150400.7.5
fixed
suse enterprise server 15 SP5
8.32-150400.7.5
fixed
suse enterprise server 15 SP6
8.32-150400.9.3.1
fixed
suse enterprise server 15 SP7
8.32-150400.9.6.1
fixed
coreutils-doc
suse enterprise desktop 15 SP4
8.32-150400.7.5
fixed
suse enterprise desktop 15 SP5
8.32-150400.7.5
fixed
suse enterprise desktop 15 SP6
8.32-150400.9.3.1
fixed
suse enterprise desktop 15 SP7
8.32-150400.9.6.1
fixed
suse enterprise sap 15 SP4
8.32-150400.7.5
fixed
suse enterprise sap 15 SP5
8.32-150400.7.5
fixed
suse enterprise sap 15 SP6
8.32-150400.9.3.1
fixed
suse enterprise sap 15 SP7
8.32-150400.9.6.1
fixed
suse enterprise server 15 SP4
8.32-150400.7.5
fixed
suse enterprise server 15 SP5
8.32-150400.7.5
fixed
suse enterprise server 15 SP6
8.32-150400.9.3.1
fixed
suse enterprise server 15 SP7
8.32-150400.9.6.1
fixed
coreutils-lang
suse enterprise desktop 15
8.29-2.12
fixed
suse enterprise desktop 15 SP1
8.29-2.12
fixed
suse enterprise desktop 15 SP2
8.29-2.12
fixed
suse enterprise desktop 15 SP3
8.32-1.2
fixed
suse enterprise desktop 15 SP4
8.32-150400.7.5
fixed
suse enterprise desktop 15 SP5
8.32-150400.7.5
fixed
suse enterprise desktop 15 SP6
8.32-150400.9.3.1
fixed
suse enterprise desktop 15 SP7
8.32-150400.9.6.1
fixed
suse enterprise sap 15
8.29-2.12
fixed
suse enterprise sap 15 SP1
8.29-2.12
fixed
suse enterprise sap 15 SP2
8.29-2.12
fixed
suse enterprise sap 15 SP3
8.32-1.2
fixed
suse enterprise sap 15 SP4
8.32-150400.7.5
fixed
suse enterprise sap 15 SP5
8.32-150400.7.5
fixed
suse enterprise sap 15 SP6
8.32-150400.9.3.1
fixed
suse enterprise sap 15 SP7
8.32-150400.9.6.1
fixed
suse enterprise server 15
8.29-2.12
fixed
suse enterprise server 15 SP1
8.29-2.12
fixed
suse enterprise server 15 SP2
8.29-2.12
fixed
suse enterprise server 15 SP3
8.32-1.2
fixed
suse enterprise server 15 SP4
8.32-150400.7.5
fixed
suse enterprise server 15 SP5
8.32-150400.7.5
fixed
suse enterprise server 15 SP6
8.32-150400.9.3.1
fixed
suse enterprise server 15 SP7
8.32-150400.9.6.1
fixed
emacs
suse enterprise desktop 15
25.3-1.124
fixed
suse enterprise desktop 15 SP1
25.3-3.3.18
fixed
suse enterprise desktop 15 SP2
25.3-3.3.18
fixed
suse enterprise desktop 15 SP3
25.3-3.6.51
fixed
suse enterprise desktop 15 SP4
27.2-150400.1.49
fixed
suse enterprise desktop 15 SP5
27.2-150400.3.6.1
fixed
suse enterprise desktop 15 SP6
27.2-150400.3.14.1
fixed
suse enterprise desktop 15 SP7
27.2-150400.3.26.1
fixed
suse enterprise sap 15
25.3-1.124
fixed
suse enterprise sap 15 SP1
25.3-3.3.18
fixed
suse enterprise sap 15 SP2
25.3-3.3.18
fixed
suse enterprise sap 15 SP3
25.3-3.6.51
fixed
suse enterprise sap 15 SP4
27.2-150400.1.49
fixed
suse enterprise sap 15 SP5
27.2-150400.3.6.1
fixed
suse enterprise sap 15 SP6
27.2-150400.3.14.1
fixed
suse enterprise sap 15 SP7
27.2-150400.3.26.1
fixed
suse enterprise server 15
25.3-1.124
fixed
suse enterprise server 15 SP1
25.3-3.3.18
fixed
suse enterprise server 15 SP2
25.3-3.3.18
fixed
suse enterprise server 15 SP3
25.3-3.6.51
fixed
suse enterprise server 15 SP4
27.2-150400.1.49
fixed
suse enterprise server 15 SP5
27.2-150400.3.6.1
fixed
suse enterprise server 15 SP6
27.2-150400.3.14.1
fixed
suse enterprise server 15 SP7
27.2-150400.3.26.1
fixed
emacs-el
suse enterprise desktop 15
25.3-1.124
fixed
suse enterprise desktop 15 SP1
25.3-3.3.18
fixed
suse enterprise desktop 15 SP2
25.3-3.3.18
fixed
suse enterprise desktop 15 SP3
25.3-3.6.51
fixed
suse enterprise desktop 15 SP4
27.2-150400.1.49
fixed
suse enterprise desktop 15 SP5
27.2-150400.3.6.1
fixed
suse enterprise desktop 15 SP6
27.2-150400.3.14.1
fixed
suse enterprise desktop 15 SP7
27.2-150400.3.26.1
fixed
suse enterprise sap 15
25.3-1.124
fixed
suse enterprise sap 15 SP1
25.3-3.3.18
fixed
suse enterprise sap 15 SP2
25.3-3.3.18
fixed
suse enterprise sap 15 SP3
25.3-3.6.51
fixed
suse enterprise sap 15 SP4
27.2-150400.1.49
fixed
suse enterprise sap 15 SP5
27.2-150400.3.6.1
fixed
suse enterprise sap 15 SP6
27.2-150400.3.14.1
fixed
suse enterprise sap 15 SP7
27.2-150400.3.26.1
fixed
suse enterprise server 15
25.3-1.124
fixed
suse enterprise server 15 SP1
25.3-3.3.18
fixed
suse enterprise server 15 SP2
25.3-3.3.18
fixed
suse enterprise server 15 SP3
25.3-3.6.51
fixed
suse enterprise server 15 SP4
27.2-150400.1.49
fixed
suse enterprise server 15 SP5
27.2-150400.3.6.1
fixed
suse enterprise server 15 SP6
27.2-150400.3.14.1
fixed
suse enterprise server 15 SP7
27.2-150400.3.26.1
fixed
emacs-info
suse enterprise desktop 15
25.3-1.124
fixed
suse enterprise desktop 15 SP1
25.3-3.3.18
fixed
suse enterprise desktop 15 SP2
25.3-3.3.18
fixed
suse enterprise desktop 15 SP3
25.3-3.6.51
fixed
suse enterprise desktop 15 SP4
27.2-150400.1.49
fixed
suse enterprise desktop 15 SP5
27.2-150400.3.6.1
fixed
suse enterprise desktop 15 SP6
27.2-150400.3.14.1
fixed
suse enterprise desktop 15 SP7
27.2-150400.3.26.1
fixed
suse enterprise sap 15
25.3-1.124
fixed
suse enterprise sap 15 SP1
25.3-3.3.18
fixed
suse enterprise sap 15 SP2
25.3-3.3.18
fixed
suse enterprise sap 15 SP3
25.3-3.6.51
fixed
suse enterprise sap 15 SP4
27.2-150400.1.49
fixed
suse enterprise sap 15 SP5
27.2-150400.3.6.1
fixed
suse enterprise sap 15 SP6
27.2-150400.3.14.1
fixed
suse enterprise sap 15 SP7
27.2-150400.3.26.1
fixed
suse enterprise server 15
25.3-1.124
fixed
suse enterprise server 15 SP1
25.3-3.3.18
fixed
suse enterprise server 15 SP2
25.3-3.3.18
fixed
suse enterprise server 15 SP3
25.3-3.6.51
fixed
suse enterprise server 15 SP4
27.2-150400.1.49
fixed
suse enterprise server 15 SP5
27.2-150400.3.6.1
fixed
suse enterprise server 15 SP6
27.2-150400.3.14.1
fixed
suse enterprise server 15 SP7
27.2-150400.3.26.1
fixed
emacs-nox
suse enterprise desktop 15
25.3-1.124
fixed
suse enterprise desktop 15 SP1
25.3-3.3.18
fixed
suse enterprise desktop 15 SP2
25.3-3.3.18
fixed
suse enterprise desktop 15 SP3
25.3-3.6.51
fixed
suse enterprise desktop 15 SP4
27.2-150400.1.49
fixed
suse enterprise desktop 15 SP5
27.2-150400.3.6.1
fixed
suse enterprise desktop 15 SP6
27.2-150400.3.14.1
fixed
suse enterprise desktop 15 SP7
27.2-150400.3.26.1
fixed
suse enterprise sap 15
25.3-1.124
fixed
suse enterprise sap 15 SP1
25.3-3.3.18
fixed
suse enterprise sap 15 SP2
25.3-3.3.18
fixed
suse enterprise sap 15 SP3
25.3-3.6.51
fixed
suse enterprise sap 15 SP4
27.2-150400.1.49
fixed
suse enterprise sap 15 SP5
27.2-150400.3.6.1
fixed
suse enterprise sap 15 SP6
27.2-150400.3.14.1
fixed
suse enterprise sap 15 SP7
27.2-150400.3.26.1
fixed
suse enterprise server 15
25.3-1.124
fixed
suse enterprise server 15 SP1
25.3-3.3.18
fixed
suse enterprise server 15 SP2
25.3-3.3.18
fixed
suse enterprise server 15 SP3
25.3-3.6.51
fixed
suse enterprise server 15 SP4
27.2-150400.1.49
fixed
suse enterprise server 15 SP5
27.2-150400.3.6.1
fixed
suse enterprise server 15 SP6
27.2-150400.3.14.1
fixed
suse enterprise server 15 SP7
27.2-150400.3.26.1
fixed
etags
suse enterprise desktop 15
25.3-1.124
fixed
suse enterprise desktop 15 SP1
25.3-3.3.18
fixed
suse enterprise desktop 15 SP2
25.3-3.3.18
fixed
suse enterprise desktop 15 SP3
25.3-3.6.51
fixed
suse enterprise desktop 15 SP4
27.2-150400.1.49
fixed
suse enterprise desktop 15 SP5
27.2-150400.3.6.1
fixed
suse enterprise desktop 15 SP6
27.2-150400.3.14.1
fixed
suse enterprise desktop 15 SP7
27.2-150400.3.26.1
fixed
suse enterprise sap 15
25.3-1.124
fixed
suse enterprise sap 15 SP1
25.3-3.3.18
fixed
suse enterprise sap 15 SP2
25.3-3.3.18
fixed
suse enterprise sap 15 SP3
25.3-3.6.51
fixed
suse enterprise sap 15 SP4
27.2-150400.1.49
fixed
suse enterprise sap 15 SP5
27.2-150400.3.6.1
fixed
suse enterprise sap 15 SP6
27.2-150400.3.14.1
fixed
suse enterprise sap 15 SP7
27.2-150400.3.26.1
fixed
suse enterprise server 15
25.3-1.124
fixed
suse enterprise server 15 SP1
25.3-3.3.18
fixed
suse enterprise server 15 SP2
25.3-3.3.18
fixed
suse enterprise server 15 SP3
25.3-3.6.51
fixed
suse enterprise server 15 SP4
27.2-150400.1.49
fixed
suse enterprise server 15 SP5
27.2-150400.3.6.1
fixed
suse enterprise server 15 SP6
27.2-150400.3.14.1
fixed
suse enterprise server 15 SP7
27.2-150400.3.26.1
fixed