The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range time value.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Linux_enterprise_debuginfo | Suse | 11-sp2 (including) | 11-sp2 (including) |
Linux_enterprise_debuginfo | Suse | 11-sp3 (including) | 11-sp3 (including) |
Linux_enterprise_debuginfo | Suse | 11-sp4 (including) | 11-sp4 (including) |
Opensuse | Opensuse | 13.2 (including) | 13.2 (including) |
Linux_enterprise_desktop | Suse | 11-sp3 (including) | 11-sp3 (including) |
Linux_enterprise_desktop | Suse | 11-sp4 (including) | 11-sp4 (including) |
Linux_enterprise_desktop | Suse | 12 (including) | 12 (including) |
Linux_enterprise_desktop | Suse | 12-sp1 (including) | 12-sp1 (including) |
Linux_enterprise_server | Suse | 11-sp2 (including) | 11-sp2 (including) |
Linux_enterprise_server | Suse | 11-sp3 (including) | 11-sp3 (including) |
Linux_enterprise_server | Suse | 11-sp4 (including) | 11-sp4 (including) |
Linux_enterprise_server | Suse | 12-sp1 (including) | 12-sp1 (including) |
Linux_enterprise_software_development_kit | Suse | 11-sp3 (including) | 11-sp3 (including) |
Linux_enterprise_software_development_kit | Suse | 11-sp4 (including) | 11-sp4 (including) |
Linux_enterprise_software_development_kit | Suse | 12 (including) | 12 (including) |
Linux_enterprise_software_development_kit | Suse | 12-sp1 (including) | 12-sp1 (including) |
Suse_linux_enterprise_server | Suse | 12 (including) | 12 (including) |
Red Hat Enterprise Linux 6 | RedHat | glibc-0:2.12-1.209.el6 | * |
Red Hat Enterprise Linux 7 | RedHat | glibc-0:2.17-196.el7 | * |
Eglibc | Ubuntu | precise | * |
Eglibc | Ubuntu | trusty | * |
Eglibc | Ubuntu | upstream | * |
Glibc | Ubuntu | upstream | * |
Glibc | Ubuntu | vivid | * |
Glibc | Ubuntu | vivid/stable-phone-overlay | * |
Glibc | Ubuntu | vivid/ubuntu-core | * |
Glibc | Ubuntu | wily | * |