CVE-2009-5155
In the GNU C Library (aka glibc or libc6) before 2.28, parse_reg_exp in posix/regcomp.c misparses alternatives, which allows attackers to… (CVE-2009-5155)
highEPSS 3.9%
Description
Metrics
Severity
high
91.29
no public PoC known
7.5
89.7 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Published
2019-02-26 02:00 UTC
—
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
gnu
glibc2.28
netapp
cloud_backup
netapp
ontap_select_deploy_administration_utility
netapp
steelstore_cloud_integrated_storage
References & sources
- https://debbugs.gnu.org/cgi/bugreport.cgi?bug=22793x_refsource_MISC
- https://security.netapp.com/advisory/ntap-20190315-0002/x_refsource_CONFIRM
- https://debbugs.gnu.org/cgi/bugreport.cgi?bug=32806x_refsource_MISC
- https://sourceware.org/bugzilla/show_bug.cgi?id=18986x_refsource_MISC
- https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=eb04c21373e2a2885f3d52ff192b0499afe3c672x_refsource_MISC
- http://git.savannah.gnu.org/cgit/gnulib.git/commit/?id=5513b40999149090987a0341c018d05d3eea1272x_refsource_MISC
- https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34238x_refsource_MISC
- https://sourceware.org/bugzilla/show_bug.cgi?id=11053x_refsource_MISC
- https://support.f5.com/csp/article/K64119434x_refsource_CONFIRM
- https://support.f5.com/csp/article/K64119434?utm_source=f5support&%3Butm_medium=RSSx_refsource_CONFIRM
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3Emailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3Emailing-listx_refsource_MLIST
IDCVE-2009-5155