Data Handling in GNU C Library (glibc) - CVE-2015-8985

 

Data Handling in GNU C Library (glibc) - CVE-2015-8985

Published: March 20, 2017 / Updated: July 18, 2020


Vulnerability identifier: #VU31436
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-8985
CWE-ID: CWE-19
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

The pop_fail_stack function in the GNU C Library (aka glibc or libc6) allows context-dependent attackers to cause a denial of service (assertion failure and application crash) via vectors related to extended regular expression processing.


Affected software

GNU C Library (glibc)
Gentoo Linux
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
glibc-32bit
glibc
glibc-info
glibc-i18ndata
glibc-html
nscd-debuginfo
nscd
glibc-profile-32bit
glibc-profile
glibc-locale-debuginfo-32bit
glibc-locale-debuginfo
glibc-locale
glibc-devel-debuginfo-32bit
glibc-devel-debuginfo
glibc-devel-32bit
glibc-devel
glibc-debugsource
glibc-debuginfo-32bit
glibc-debuginfo
glibc-locale-32bit
glibc-utils-debuginfo
glibc-utils-src-debugsource
glibc-32bit-debuginfo
glibc-devel-32bit-debuginfo
glibc-locale-base-32bit
glibc-locale-base-32bit-debuginfo
glibc-utils
glibc-locale-base-debuginfo
glibc-locale-base
glibc-extra-debuginfo
glibc-extra
glibc-devel-static
EMC ECS
EMC Cloud Tiering Appliance
RecoverPoint for VMs
RSA Authentication Manager

How to mitigate CVE-2015-8985

Install update from vendor's website.

GNU C Library (glibc) - update to 2.28
glibc-32bit - addressed in versions 2.22-114.22.1, 2.26-13.65.1
glibc - addressed in versions 2.22-114.22.1, 2.26-13.65.1
glibc-info - addressed in versions 2.22-114.22.1, 2.26-13.65.1
glibc-i18ndata - addressed in versions 2.22-114.22.1, 2.26-13.65.1
glibc-html - update to 2.22-114.22.1
nscd-debuginfo - addressed in versions 2.22-114.22.1, 2.26-13.65.1
nscd - addressed in versions 2.22-114.22.1, 2.26-13.65.1
glibc-profile-32bit - update to 2.22-114.22.1
glibc-profile - addressed in versions 2.22-114.22.1, 2.26-13.65.1
glibc-locale-debuginfo-32bit - update to 2.22-114.22.1
glibc-locale-debuginfo - update to 2.22-114.22.1
glibc-locale - addressed in versions 2.22-114.22.1, 2.26-13.65.1
glibc-devel-debuginfo-32bit - update to 2.22-114.22.1
glibc-devel-debuginfo - addressed in versions 2.22-114.22.1, 2.26-13.65.1
glibc-devel-32bit - addressed in versions 2.22-114.22.1, 2.26-13.65.1
glibc-devel - addressed in versions 2.22-114.22.1, 2.26-13.65.1
glibc-debugsource - addressed in versions 2.22-114.22.1, 2.26-13.65.1
glibc-debuginfo-32bit - update to 2.22-114.22.1
glibc-debuginfo - addressed in versions 2.22-114.22.1, 2.26-13.65.1
glibc-locale-32bit - update to 2.22-114.22.1
glibc-utils-debuginfo - update to 2.26-13.65.1
glibc-utils-src-debugsource - update to 2.26-13.65.1
glibc-32bit-debuginfo - update to 2.26-13.65.1
glibc-devel-32bit-debuginfo - update to 2.26-13.65.1
glibc-locale-base-32bit - update to 2.26-13.65.1
glibc-locale-base-32bit-debuginfo - update to 2.26-13.65.1
glibc-utils - update to 2.26-13.65.1
glibc-locale-base-debuginfo - update to 2.26-13.65.1
glibc-locale-base - update to 2.26-13.65.1
glibc-extra-debuginfo - update to 2.26-13.65.1
glibc-extra - update to 2.26-13.65.1
glibc-devel-static - update to 2.26-13.65.1
EMC ECS - update to 3.8.0.2
RecoverPoint for VMs - update to 6.0.SP1.P1
RSA Authentication Manager - update to 8.7 Patch 3
EMC Cloud Tiering Appliance - update to 13.1.0.2.29

External References

Related Security Bulletins