UBUNTU-CVE-2015-2305
Dashboard / Vulnerabilities / UBUNTU-CVE-2015-2305
UBUNTU-CVE-2015-2305
Summary:
Details: Integer overflow in the regcomp implementation in the Henry Spencer BSD regex library (aka rxspencer) alpha3.8.g5 on 32-bit platforms, as used in NetBSD through 6.1.5 and other products, might allow context-dependent attackers to execute arbitrary code via a large regular expression that leads to a heap-based buffer overflow.
References: https://ubuntu.com/security/CVE-2015-2305, http://www.kb.cert.org/vuls/id/695940, https://guidovranken.wordpress.com/2015/02/04/full-disclosure-heap-overflow-in-h-spencers-regex-library-on-32-bit-systems/, https://ubuntu.com/security/notices/USN-2572-1, https://ubuntu.com/security/notices/USN-2594-1, https://www.cve.org/CVERecord?id=CVE-2015-2305
Affected packages
Package
Name: clamav
Purl: pkg:deb/ubuntu/[email protected]+dfsg-0ubuntu0.14.04.1?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
