CVE-2015-8983 PUBLISHED

Integer overflow in the _IO_wstr_overflow function in libio/wstrops.c in the GNU C Library (aka glibc or libc6) before 2.22 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors related to computing a size in bytes, which triggers a heap-based buffer overflow.

EPSS 0.52% · 66.8th percentile

Risk Scores

EPSS Score
0.52%
66.8th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSeglibc0, 2.17-93ubuntu4, 2.18-0ubuntu1

Timeline

References

Open in Interactive Console →