CVE-2019-9169
In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an att… (CVE-2019-9169)
criticalEPSS 4.7%
Description
Metrics
Severity
critical
103.76
no public PoC known
9.8
91.3 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Published
2019-02-26 02:00 UTC
—
Affected operating systems
linux
canonical / ubuntu_linux16.04
linux
canonical / ubuntu_linux18.04
linux
canonical / ubuntu_linux19.10
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
gnu
glibc2.29
mcafee
web_gateway7.7.2.0 – 7.7.2.21
mcafee
web_gateway7.8.2.0 – 7.8.2.8
mcafee
web_gateway8.0.0 – 8.1.1
netapp
cloud_backup
netapp
ontap_select_deploy_administration_utility
netapp
steelstore_cloud_integrated_storage
References & sources
- http://www.securityfocus.com/bid/107160vdb-entryx_refsource_BID
- https://security.gentoo.org/glsa/202006-04vendor-advisoryx_refsource_GENTOO
- https://usn.ubuntu.com/4416-1/vendor-advisoryx_refsource_UBUNTU
- https://kc.mcafee.com/corporate/index?page=content&id=SB10278x_refsource_CONFIRM
- https://www.oracle.com/security-alerts/cpuapr2022.htmlx_refsource_MISC
- https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commit%3Bh=583dd860d5b833037175247230a328f0050dbfe9x_refsource_MISC
- https://security.netapp.com/advisory/ntap-20190315-0002/x_refsource_CONFIRM
- https://sourceware.org/bugzilla/show_bug.cgi?id=24114x_refsource_MISC
- https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34142x_refsource_MISC
- https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34140x_refsource_MISC
- https://support.f5.com/csp/article/K54823184x_refsource_CONFIRM
IDCVE-2019-9169