In the GNU C Library (aka glibc or libc6) before 2.28, parse_reg_exp in posix/regcomp.c misparses alternatives, which allows attackers to cause a denial of service (assertion failure and application exit) or trigger an incorrect result by attempting a regular-expression match.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2019-02-26T02:00:00
Updated: 2024-08-07T07:32:23.298Z
Reserved: 2019-02-25T00:00:00
Link: CVE-2009-5155
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-02-26T02:29:00.277
Modified: 2024-11-21T01:11:17.400
Link: CVE-2009-5155
Redhat