CVE-2015-20109: Medium severity gnu c library vulnerability
endpattern (called from internalfnmatch) in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent attackers to cause a denial of service (application crash), as demonstrated by use of the fnmatch library function with the (!() pattern. NOTE: this is not the same as CVE-2015-8984; also, some Linux distributions have fixed CVE-2015-8984 but have not fixed this additional fnmatch issue.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2015-20109.
What is the name of the affected software?
The affected software is the GNU C Library (aka glibc or libc6).
What is the severity rating of CVE-2015-20109?
The severity rating of CVE-2015-20109 is medium (5.5).
How can context-dependent attackers exploit CVE-2015-20109?
Context-dependent attackers can exploit CVE-2015-20109 by causing a denial of service (application crash) through the use of the fnmatch library function with the **(!() pattern.
How can I fix CVE-2015-20109?
To fix CVE-2015-20109, you should update the GNU C Library to version 2.22 or later.