CVE-2009-5155

In the GNU C Library (aka glibc or libc6) before 2.28, parse_reg_exp in posix/regcomp.c misparses alternatives, which allows attackers to… (CVE-2009-5155)

Description

In the GNU C Library (aka glibc or libc6) before 2.28, parse_reg_exp in posix/regcomp.c misparses alternatives, which allows attackers to cause a denial of service (assertion failure and application exit) or trigger an incorrect result by attempting a regular-expression match.

Source: CVELISTV5NVD

Metrics

Severity
high
no public PoC known
7.5
Source: nvd-v3
89.7 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
3.9 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2019-02-26 02:00 UTC

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • gnu

    glibc2.28

  • netapp

    cloud_backup

  • netapp

    ontap_select_deploy_administration_utility

  • netapp

    steelstore_cloud_integrated_storage

References & sources

IDCVE-2009-5155