Vulnerability Name: | CVE-2018-20796 (CCN-158013) | ||||||||||||||||||||||||||||||||||||
Assigned: | 2019-01-20 | ||||||||||||||||||||||||||||||||||||
Published: | 2019-01-20 | ||||||||||||||||||||||||||||||||||||
Updated: | 2019-11-05 | ||||||||||||||||||||||||||||||||||||
Summary: | In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\227|)(\\1\\1|t1|\\\2537)+' in grep. | ||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) 6.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:U/RC:R)
3.5 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:U/RC:R)
| ||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-674 | ||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2018-20796 Source: BID Type: Third Party Advisory, VDB Entry 107160 Source: CCN Type: GNU bug report logs - #34141 Stackoverflow triggered at lib/regexec.c:1948 Source: MISC Type: Exploit, Mailing List, Vendor Advisory https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141 Source: XF Type: UNKNOWN gnu-glibc-cve201820796-dos(158013) Source: MISC Type: Exploit, Mailing List, Vendor Advisory https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html Source: CONFIRM Type: Patch, Third Party Advisory https://security.netapp.com/advisory/ntap-20190315-0002/ Source: CONFIRM Type: UNKNOWN https://support.f5.com/csp/article/K26346590?utm_source=f5support&utm_medium=RSS Source: CCN Type: GNU Web site The GNU C Library (glibc) Source: CCN Type: IBM Security Bulletin 1087113 (Security 1G Network Active Bypass) IBM Security Proventia Network Active Bypass is affected by glibc vulnerabilities (CVE-2018-20796, CVE-2019-9169) Source: CCN Type: IBM Security Bulletin 1143466 (Watson Studio Local) Multiple Vulnerabilities in GNU C Library affects IBM Watson Studio Local Source: CCN Type: IBM Security Bulletin 6982841 (Netcool Operations Insight) Netcool Operations Insight v1.6.8 addresses multiple security vulnerabilities. Source: CCN Type: WhiteSource Vulnerability Database CVE-2018-20796 | ||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
BACK |