First published: Thu Feb 26 2015(Updated: )
It was reported [1] that scanf and related functions are crashing due to a bug [2] in glibc. [1]: <a href="http://seclists.org/oss-sec/2015/q1/686">http://seclists.org/oss-sec/2015/q1/686</a> [2]: <a href="https://sourceware.org/bugzilla/show_bug.cgi?id=13138">https://sourceware.org/bugzilla/show_bug.cgi?id=13138</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/glibc | <2.15 | 2.15 |
GNU C Library (glibc) | <=2.14.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-5320 has been classified as a moderate severity vulnerability that can lead to application crashes.
CVE-2011-5320 affects glibc versions prior to 2.15 as well as GNU C Library versions up to 2.14.1.
To mitigate CVE-2011-5320, upgrade glibc to version 2.15 or later.
The main symptom of CVE-2011-5320 is unexpected application crashes when using scanf and related functions.
There are no effective workarounds for CVE-2011-5320 other than updating to the fixed version.