CVE-2015-8776: Critical severity suse linux enterprise debuginfo vulnerability
It was found that out-of-range time values passed to the strftime function may cause it to crash, leading to a denial of service, or potentially disclosure information.
Upstream bug:
https://sourceware.org/bugzilla/showbug.cgi?id=18985
CVE assignment:
http://seclists.org/oss-sec/2016/q1/153
Other sources
The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range time value.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8776?
CVE-2015-8776 has a moderate severity rating as it can lead to application crashes or potential information disclosure.
How do I fix CVE-2015-8776?
To fix CVE-2015-8776, upgrade the GNU C Library to version 2.23 or later.
Which software is affected by CVE-2015-8776?
CVE-2015-8776 affects various versions of GNU C Library, particularly those before version 2.23.
Can CVE-2015-8776 be exploited remotely?
CVE-2015-8776 is considered a context-dependent vulnerability, meaning exploitation typically requires specific conditions to be met.
What are the potential impacts of CVE-2015-8776?
Successful exploitation of CVE-2015-8776 can lead to application crashes or exposure of sensitive information.