AZL-40934
Dashboard / Vulnerabilities / AZL-40934
Summary: CVE-2015-1473 affecting package dietlibc for versions less than 0.34-7
Details: The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during a risk-management decision for use of the alloca function, which might allow context-dependent attackers to cause a denial of service (segmentation violation) or overwrite memory locations beyond the stack boundary via a long line containing wide characters that are improperly handled in a wscanf call.
References: https://nvd.nist.gov/vuln/detail/CVE-2015-1473
Affected packages
Package
Name: dietlibc
Purl: pkg:rpm/azure-linux/dietlibc
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -0.34-7
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
