CVE-2015-5277
Summary
| CVE | CVE-2015-5277 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-12-17 19:59:00 UTC |
| Updated | 2023-02-12 23:15:00 UTC |
| Description | The get_contents function in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) before 2.20 might allow local users to cause a denial of service (heap corruption) or gain privileges via a long line in the NSS files database. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Bug 1262914 – CVE-2015-5277 glibc: data corruption while reading the NSS files database |
CONFIRM |
bugzilla.redhat.com |
|
| GNU glibc CVE-2015-5277 Local Heap Based Buffer Overflow Vulnerability |
BID |
www.securityfocus.com |
|
| CVE-2015-5277 - Red Hat Customer Portal |
MISC |
access.redhat.com |
|
| USN-2985-2: GNU C Library regression | Ubuntu |
UBUNTU |
www.ubuntu.com |
|
| Full Disclosure: SEC Consult SA-20190904-0 :: Multiple vulnerabilities in Cisco router series RV34X, RV26X and RV16X |
FULLDISC |
seclists.org |
|
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
|
| Red Hat Customer Portal |
MISC |
access.redhat.com |
|
| Cisco Device Hardcoded Credentials / GNU glibc / BusyBox ≈ Packet Storm |
MISC |
packetstormsecurity.com |
|
| Glibc Heap Corruption in nss_files Backend Lets Local Users Gain Elevated Privileges - SecurityTracker |
SECTRACK |
www.securitytracker.com |
|
| Bugtraq: SEC Consult SA-20190904-0 :: Multiple vulnerabilities in Cisco router series RV34X, RV26X and RV16X |
BUGTRAQ |
seclists.org |
|
| Allan McRae - The GNU C Library version 2.20 is now available |
MLIST |
sourceware.org |
|
| Oracle Linux Bulletin - October 2015 |
CONFIRM |
www.oracle.com |
|
| USN-2985-1: GNU C Library vulnerabilities | Ubuntu |
UBUNTU |
www.ubuntu.com |
|
| 17079 – (CVE-2015-5277) nss_files heap-based buffer overflow with small buffer (CVE-2015-5277) |
CONFIRM |
sourceware.org |
|
| Red Hat Customer Portal |
MISC |
access.redhat.com |
|
| GNU C Library: Multiple vulnerabilities (GLSA 201702-11) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710558 Gentoo Linux GNU C Library Multiple Vulnerabilities (GLSA 201702-11)