Wind River Support Network

HomeDefectsLIN10-2304
Fixed

LIN10-2304 : Security Advisory - glibc - CVE-2017-15671

Created: Oct 22, 2017    Updated: Sep 13, 2022
Resolved Date: Jul 11, 2018
Previous ID: LIN9-5634
Found In Version: 10.17.41.1
Fix Version: 10.17.41.9
Severity: Standard
Applicable for: Wind River Linux LTS 17
Component/s: Toolchain

Description

The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27, when invoked with GLOB_TILDE, could skip freeing allocated memory when processing the ~ operator with a long user name, potentially leading to a denial of service (memory leak).

https://nvd.nist.gov/vuln/detail/CVE-2017-15671

Other Downloads


CVEs


Live chat
Online