UBUNTU-CVE-2015-20109
Dashboard / Vulnerabilities / UBUNTU-CVE-2015-20109
UBUNTU-CVE-2015-20109
Summary:
Details: end_pattern (called from internal_fnmatch) in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent attackers to cause a denial of service (application crash), as demonstrated by use of the fnmatch library function with the **(!() pattern. NOTE: this is not the same as CVE-2015-8984; also, some Linux distributions have fixed CVE-2015-8984 but have not fixed this additional fnmatch issue.
References: https://ubuntu.com/security/CVE-2015-20109, https://sourceware.org/bugzilla/show_bug.cgi?id=18036, https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=c2c6d39fab901c97c18fa3a3a3658d9dc3f7df61, https://www.cve.org/CVERecord?id=CVE-2015-20109, https://ubuntu.com/security/notices/USN-6762-1
Affected packages
Package
Name: eglibc
Purl: pkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
