In the GNU C Library (aka glibc or libc6) before 2.28, parse_reg_exp in posix/regcomp.c misparses alternatives, which allows attackers to cause a denial of service (assertion failure and application exit) or trigger an incorrect result by attempting a regular-expression match.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Glibc | Gnu | * | 2.28 (excluding) |
Eglibc | Ubuntu | esm-infra-legacy/trusty | * |
Eglibc | Ubuntu | precise/esm | * |
Eglibc | Ubuntu | trusty | * |
Eglibc | Ubuntu | trusty/esm | * |
Eglibc | Ubuntu | upstream | * |
Glibc | Ubuntu | bionic | * |
Glibc | Ubuntu | esm-infra/bionic | * |
Glibc | Ubuntu | upstream | * |
Glibc | Ubuntu | xenial | * |
Gnulib | Ubuntu | bionic | * |
Gnulib | Ubuntu | cosmic | * |
Gnulib | Ubuntu | disco | * |
Gnulib | Ubuntu | esm-apps/bionic | * |
Gnulib | Ubuntu | esm-apps/xenial | * |
Gnulib | Ubuntu | trusty | * |
Gnulib | Ubuntu | upstream | * |
Gnulib | Ubuntu | xenial | * |