In the GNU C Library (aka glibc or libc6) before 2.28, parse_reg_exp in posix/regcomp.c misparses alternatives, which allows attackers to cause a denial of service (assertion failure and application exit) or trigger an incorrect result by attempting a regular-expression match.
References
Information
Published : 2019-02-25 18:29
Updated : 2021-06-29 08:15
NVD link : CVE-2009-5155
Mitre link : CVE-2009-5155
JSON object : View
CWE
CWE-19
Data Processing Errors
Products Affected
netapp
- cloud_backup
- steelstore_cloud_integrated_storage
- ontap_select_deploy_administration_utility
gnu
- glibc