In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-insensitive regular-expression match.
2019-02-26T02:29:00.497
2024-11-21T04:51:07.870
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gnu | glibc | ≤ 2.29 | Yes |
Application | netapp | cloud_backup | * | Yes |
Application | netapp | ontap_select_deploy_administration_utility | - | Yes |
Application | netapp | steelstore_cloud_integrated_storage | - | Yes |
Application | mcafee | web_gateway | < 7.7.2.21 | Yes |
Application | mcafee | web_gateway | < 7.8.2.8 | Yes |
Application | mcafee | web_gateway | < 8.1.1 | Yes |
Operating System | canonical | ubuntu_linux | 16.04 | Yes |
Operating System | canonical | ubuntu_linux | 18.04 | Yes |
Operating System | canonical | ubuntu_linux | 19.10 | Yes |