CVE-2015-5218: Buffer Overflow

Published Sep 2, 2015
·
Updated

A flaw was reported in colcrt:

When running colcrt with a big input it crashes because of a global-buffer-overflow caused by a global variable 'page' defined in 'text-utils/colcrt.c:73:9

It is unclear whether this can be used to execute code on the system.

Proposed patches:

https://github.com/kerolasa/lelux-utiliteetit/commit/70e3fcf293c1827a2655a86584ab13075124a8a8 https://github.com/kerolasa/lelux-utiliteetit/commit/d883d64d96ab9bef510745d064a351145b9babec

Other sources

Buffer overflow in text-utils/colcrt.c in colcrt in util-linux before 2.27 allows local users to cause a denial of service (crash) via a crafted file, related to the page global variable.

MITRE

Affected Software

5 affected componentsFixes available
redhat/util-linux<2.27
2.27
kernel util-linux<=2.22
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
Opensuse Project Leap=42.1

Event History

Nov 9, 2015
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2015-5218?

The severity of CVE-2015-5218 is not clearly defined, but it involves a global buffer overflow that may lead to crashes.

2

How do I fix CVE-2015-5218?

To fix CVE-2015-5218, you should upgrade to util-linux version 2.27 or later.

3

What software is affected by CVE-2015-5218?

CVE-2015-5218 affects versions of util-linux prior to 2.27, as well as specific versions of openSUSE.

4

Can CVE-2015-5218 be exploited to execute code?

It is unclear whether CVE-2015-5218 can be exploited to execute code on the system.

5

What is the nature of the flaw in CVE-2015-5218?

The flaw in CVE-2015-5218 is a global buffer overflow that occurs when colcrt is run with large inputs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203