Do your applications use this vulnerable package?
Test your applications
Overview
The pop_fail_stack function in the GNU C Library (aka glibc or libc6) allows context-dependent attackers to cause a denial of service (assertion failure and application crash) via vectors related to extended regular expression processing.
References
CVSS Score
5.9
low severity
-
Attack VectorNetwork
-
Attack ComplexityHigh
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityNone
-
IntegrityNone
-
AvailabilityHigh
- CVE
- CVE-2015-8985
- CWE
- CWE-19
- Snyk ID
- SNYK-UBUNTU1604-GLIBC-356502
- Disclosed
- 20 Mar, 2017
- Published
- 20 Mar, 2017