CVE-2017-15671 PUBLISHED

The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27, when invoked with GLOB_TILDE, could skip freeing allocated memory when processing the ~ operator with a long user name, potentially leading to a denial of service (memory leak).

EPSS 0.40% · 60.6th percentile

Risk Scores

EPSS Score
0.40%
60.6th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSeglibc0, 2.17-93ubuntu4, 2.18-0ubuntu1

Timeline

References

Open in Interactive Console →