6.8

CVE-2015-2305

Exploit
Integer overflow in the regcomp implementation in the Henry Spencer BSD regex library (aka rxspencer) alpha3.8.g5 on 32-bit platforms, as used in NetBSD through 6.1.5 and other products, might allow context-dependent attackers to execute arbitrary code via a large regular expression that leads to a heap-based buffer overflow.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Rxspencer Project ≫ Rxspencer Version 3.8.g5
Canonical ≫ Ubuntu Linux Version 10.04 SwEdition -
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition -
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 14.10
Canonical ≫ Ubuntu Linux Version 15.04
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Opensuse ≫ Opensuse Version 13.1
Opensuse ≫ Opensuse Version 13.2
Php ≫ Php Version >= 5.4.0 < 5.4.39
Php ≫ Php Version >= 5.5.0 < 5.5.23
Php ≫ Php Version >= 5.6.0 < 5.6.7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.34% 0.944
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-190 Integer Overflow or Wraparound

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

http://lists.opensuse.org/opensuse-updates/2015-05/msg00024.html
Third Party Advisory
Mailing List
http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
Third Party Advisory
http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html
Third Party Advisory
Mailing List
https://support.apple.com/HT205267
Third Party Advisory
http://php.net/ChangeLog-5.php
Vendor Advisory
http://marc.info/?l=bugtraq&m=143403519711434&w=2
Third Party Advisory
Mailing List
http://rhn.redhat.com/errata/RHSA-2015-1053.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1066.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00026.html
Third Party Advisory
Mailing List
http://www.debian.org/security/2015/dsa-3195
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00005.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-updates/2015-04/msg00002.html
Third Party Advisory
Mailing List
http://blog.clamav.net/2015/04/clamav-0987-has-been-released.html
Third Party Advisory
http://openwall.com/lists/oss-security/2015/02/07/14
Third Party Advisory
Mailing List
http://openwall.com/lists/oss-security/2015/03/11/8
Third Party Advisory
Mailing List
http://www.kb.cert.org/vuls/id/695940
Third Party Advisory
US Government Resource
http://www.securityfocus.com/bid/72611
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1031947
Third Party Advisory
VDB Entry
http://www.ubuntu.com/usn/USN-2572-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-2594-1
Third Party Advisory
https://guidovranken.wordpress.com/2015/02/04/full-disclosure-heap-overflow-in-h-spencers-regex-library-on-32-bit-systems/
Third Party Advisory
Exploit