CVE-2009-5155: High severity GNU glibc vulnerability
Published Feb 26, 2019
·Updated
In the GNU C Library (aka glibc or libc6) before 2.28, parseregexp in posix/regcomp.c misparses alternatives, which allows attackers to cause a denial of service (assertion failure and application exit) or trigger an incorrect result by attempting a regular-expression match.
Affected Software
11 affected componentsFixes available
GNU glibc<2.28
NetApp Steelstore Cloud Integrated Storage
NetApp ONTAP Select Deploy administration utility
NetApp Cloud Backup
debian/glibc
2.31-13+deb11u112.31-13+deb11u102.36-9+deb12u102.36-9+deb12u72.41-7
debian/gnulib
20210102~ebaa53c-120230209+stable-120250303-1
F5 BIG-IP=17.5.0, >=17.1.0<=17.1.2
17.5.1
F5 BIG-IP>=16.1.0<=16.1.6
F5 BIG-IP>=15.1.0<=15.1.10
F5 BIG-IQ Centralized Management>=8.3.0<=8.4.0
8.4.1
F5 Traffix SDC=5.2.0
Remediation
Patch Available
Event History
Feb 26, 2019
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Mar 25, 2019
Advisory Published
via F5·03:17 AM
Data Sourced
via F5·03:17 AM
DescriptionSeverityWeaknessAffected Software
May 6, 2024
Data Sourced
via Launchpad·03:10 PM
Description
Sep 15, 2024
Data Sourced
via Ubuntu·03:31 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2009-5155?
CVE-2009-5155 is a vulnerability in the GNU C Library (glibc) before version 2.28.
2
What is the severity of CVE-2009-5155?
CVE-2009-5155 has a severity rating of 7.5 (high).
3
How does CVE-2009-5155 impact affected software?
CVE-2009-5155 can cause a denial of service (assertion failure and application exit) or trigger an incorrect result by attempting a regular-expression match.
4
How can I fix CVE-2009-5155?
To fix CVE-2009-5155, update to GNU C Library version 2.28 or later.
5
Where can I find more information about CVE-2009-5155?
More information about CVE-2009-5155 can be found at the following references: [1] [2] [3].