CVE-2009-5155
In the GNU C Library (aka glibc or libc6) before 2.28, parse_reg_exp in posix/regcomp.c misparses alternatives, which allows attackers to cause a denial of service (assertion failure and application exit) or trigger an incorrect result by attempting a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.91%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the GNU C Library (aka glibc or libc6) before 2.28, parse_reg_exp in posix/regcomp.c misparses alternatives, which allows attackers to cause a denial of service (assertion failure and application exit) or trigger an incorrect result by attempting a regular-expression match.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 3.91% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-19
- Affected
- gnu/glibc · netapp/cloud backup · netapp/ontap select deploy administration utility · netapp/steelstore cloud integrated storage
- Source
- cve@mitre.org
References
- http://git.savannah.gnu.org/cgit/gnulib.git/commit/?id=5513b40999149090987a0341c018d05d3eea1272Mailing List, Patch, Vendor Advisory
- https://debbugs.gnu.org/cgi/bugreport.cgi?bug=22793Mailing List, Vendor Advisory
- https://debbugs.gnu.org/cgi/bugreport.cgi?bug=32806Exploit, Mailing List, Vendor Advisory
- https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34238Exploit, Mailing List, Vendor Advisory
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E
- https://security.netapp.com/advisory/ntap-20190315-0002/Patch, Third Party Advisory
- https://sourceware.org/bugzilla/show_bug.cgi?id=11053Exploit, Issue Tracking, Third Party Advisory
- https://sourceware.org/bugzilla/show_bug.cgi?id=18986Exploit, Issue Tracking, Third Party Advisory
- https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=eb04c21373e2a2885f3d52ff192b0499afe3c672
- https://support.f5.com/csp/article/K64119434
- https://support.f5.com/csp/article/K64119434?utm_source=f5support&%3Butm_medium=RSS
- http://git.savannah.gnu.org/cgit/gnulib.git/commit/?id=5513b40999149090987a0341c018d05d3eea1272Mailing List, Patch, Vendor Advisory
- https://debbugs.gnu.org/cgi/bugreport.cgi?bug=22793Mailing List, Vendor Advisory
- https://debbugs.gnu.org/cgi/bugreport.cgi?bug=32806Exploit, Mailing List, Vendor Advisory
- https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34238Exploit, Mailing List, Vendor Advisory
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E
- https://security.netapp.com/advisory/ntap-20190315-0002/Patch, Third Party Advisory
- https://sourceware.org/bugzilla/show_bug.cgi?id=11053Exploit, Issue Tracking, Third Party Advisory
- https://sourceware.org/bugzilla/show_bug.cgi?id=18986Exploit, Issue Tracking, Third Party Advisory
- https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=eb04c21373e2a2885f3d52ff192b0499afe3c672
- https://support.f5.com/csp/article/K64119434
- https://support.f5.com/csp/article/K64119434?utm_source=f5support&%3Butm_medium=RSS
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.