Wind River Support Network


LIN10-2304 : Security Advisory - glibc - CVE-2017-15671

Created: Oct 23, 2017    Updated: Dec 3, 2018
Resolved Date: Jul 11, 2018
Previous ID: LIN9-5634
Found In Version:
Fix Version:
Severity: Standard
Applicable for: Wind River Linux LTS 17
Component/s: Toolchain


The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27, when invoked with GLOB_TILDE, could skip freeing allocated memory when processing the ~ operator with a long user name, potentially leading to a denial of service (memory leak).

Other Downloads

Live chat