In the GNU C Library (aka glibc or libc6) before 2.28, parse_reg_exp in posix/regcomp.c misparses alternatives, which allows attackers to cause a denial of service (assertion failure and application exit) or trigger an incorrect result by attempting a regular-expression match.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-02-26T02:00:00

Updated: 2024-08-07T07:32:23.298Z

Reserved: 2019-02-25T00:00:00

Link: CVE-2009-5155

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-02-26T02:29:00.277

Modified: 2023-11-07T02:04:57.977

Link: CVE-2009-5155

cve-icon Redhat

Severity : Moderate

Publid Date: 2019-03-20T00:00:00Z

Links: CVE-2009-5155 - Bugzilla