CVE-2015-8984: Medium severity gnu c library (glibc) vulnerability
Published Mar 20, 2017
·Updated
Last updated 24 July 2024
Other sources
The fnmatch function in the GNU C Library (aka glibc or libc6) before ...
— Debian
Affected Software
2 affected componentsFixes available
GNU glibc<=2.21
debian/glibc
2.31-13+deb11u112.31-13+deb11u102.36-9+deb12u102.36-9+deb12u72.41-6
Remediation
Patch Available
Patch Available
Patch Available
Event History
Mar 20, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:15 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:10 AM
RemedyDescriptionSeverityAffected Software
Mar 31, 2025
Data Sourced
via Debian·03:26 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2015-8984?
CVE-2015-8984 has a severity level that may lead to a denial of service through application crashes.
2
How do I fix CVE-2015-8984?
To remediate CVE-2015-8984, update the GNU C Library (glibc) to version 2.22 or later.
3
Which versions of glibc are affected by CVE-2015-8984?
CVE-2015-8984 affects glibc versions prior to 2.22, specifically versions up to and including 2.21.
4
What does CVE-2015-8984 exploit?
CVE-2015-8984 exploits the fnmatch function, causing out-of-bounds reads through malformed patterns.
5
Can CVE-2015-8984 be exploited remotely?
CVE-2015-8984 requires context-dependent conditions to be exploited, typically via local applications.