Package: libc6
Version: 2.24-17
Severity: important
Tags: security

Please see http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15671:
The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 
2.27,
when invoked with GLOB_TILDE, could skip freeing allocated memory when 
processing
the ~ operator with a long user name, potentially leading to a denial of
service (memory leak).

Upstream bug is https://sourceware.org/bugzilla/show_bug.cgi?id=22325

Fix is here: 
https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=c66c908230169c1bab1f83b071eb585baa214b9f

Cheers,
        Moritz

_______________________________________________
Secure-testing-team mailing list
Secure-testing-team@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-team

Reply via email to