Henry Spencer Regex Library 'regcomp.c' Heap Overflow Vulnerability
BID:72611
Info
Henry Spencer Regex Library 'regcomp.c' Heap Overflow Vulnerability
| Bugtraq ID: | 72611 |
| Class: | Design Error |
| CVE: |
CVE-2015-2305 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 04 2015 12:00AM |
| Updated: | Jul 05 2016 10:05PM |
| Credit: | Guido Vranken |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 HP HP-UX B.11.31 Apple Mac Os X 10.7.4 Apple Mac Os X 10.7.3 Apple Mac Os X 10.7.1 |
| Not Vulnerable: | |
Discussion
Henry Spencer Regex Library 'regcomp.c' Heap Overflow Vulnerability
Henry Spencer Regex Library is prone to a heap-based buffer-overflow vulnerability.
An attacker may leverage this issue to perform certain unauthorized actions in the context of the affected application.
Henry Spencer Regex Library is prone to a heap-based buffer-overflow vulnerability.
An attacker may leverage this issue to perform certain unauthorized actions in the context of the affected application.
Exploit / POC
Henry Spencer Regex Library 'regcomp.c' Heap Overflow Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.