Bug 1262914 (CVE-2015-5277) - CVE-2015-5277 glibc: data corruption while reading the NSS files database
Summary: CVE-2015-5277 glibc: data corruption while reading the NSS files database
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2015-5277
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1099235 1263134 1263352 1275920
Blocks: 1262918
TreeView+ depends on / blocked
 
Reported: 2015-09-14 15:36 UTC by Florian Weimer
Modified: 2021-02-17 04:56 UTC (History)
15 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
It was discovered that the nss_files backend for the Name Service Switch in glibc would return incorrect data to applications or corrupt the heap (depending on adjacent heap contents). A local attacker could potentially use this flaw to execute arbitrary code on the system.
Clone Of:
Environment:
Last Closed: 2015-11-20 05:58:06 UTC


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Bugzilla 1261023 0 medium CLOSED login via ssh as remote user often fails with: "Write failed: Broken pipe" 2021-02-22 00:41:40 UTC
Red Hat Product Errata RHSA-2015:2172 0 normal SHIPPED_LIVE Important: glibc security update 2015-11-19 20:45:24 UTC
Red Hat Product Errata RHSA-2015:2589 0 normal SHIPPED_LIVE Important: glibc security update 2015-12-09 13:57:25 UTC
Sourceware 17079 0 P2 RESOLVED nss_files heap-based buffer overflow with small buffer (CVE-2015-5277) 2020-02-13 09:53:56 UTC

Internal Links: 1261023

Description Florian Weimer 2015-09-14 15:36:19 UTC
It was discovered that the nss_files backend for the Name Service Switch in glibc would return incorrect data to applications or corrupt the heap (depending on adjacent heap contents), potentially resulting in arbitrary code execution.

Comment 1 Florian Weimer 2015-09-14 15:37:37 UTC
External references:

https://sourceware.org/bugzilla/show_bug.cgi?id=17079

Comment 10 Ján Rusnačko 2015-11-13 08:38:59 UTC
Acknowledgements:

This issue was discovered by Sumit Bose and Lukáš Slebodník of Red Hat.

Comment 11 errata-xmlrpc 2015-11-19 15:55:50 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2015:2172 https://rhn.redhat.com/errata/RHSA-2015-2172.html

Comment 15 errata-xmlrpc 2015-12-09 08:58:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7.1 EUS - Server and Compute Node Only
  Red Hat Enterprise Linux 7.1 EUS  - Server and Compute Node Only

Via RHSA-2015:2589 https://rhn.redhat.com/errata/RHSA-2015-2589.html


Note You need to log in before you can comment on or make changes to this bug.