CVE-2009-5155

HIGH

glibc < 2.28 - Denial of Service via Regular Expression Parsing

Title source: llm
STIX 2.1

Description

In the GNU C Library (aka glibc or libc6) before 2.28, parse_reg_exp in posix/regcomp.c misparses alternatives, which allows attackers to cause a denial of service (assertion failure and application exit) or trigger an incorrect result by attempting a regular-expression match.

References (12)

Core 12
Core References
Mailing List, Vendor Advisory x_refsource_misc
https://debbugs.gnu.org/cgi/bugreport.cgi?bug=22793
Patch, Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20190315-0002/
Exploit, Mailing List, Vendor Advisory x_refsource_misc
https://debbugs.gnu.org/cgi/bugreport.cgi?bug=32806
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://sourceware.org/bugzilla/show_bug.cgi?id=18986
Exploit, Mailing List, Vendor Advisory x_refsource_misc
https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34238
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://sourceware.org/bugzilla/show_bug.cgi?id=11053
Vendor Advisory x_refsource_confirm
https://support.f5.com/csp/article/K64119434

Scores

CVSS v3 7.5
EPSS 0.0135
EPSS Percentile 80.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-19
Status published
Products (4)
gnu/glibc < 2.28
netapp/cloud_backup
netapp/ontap_select_deploy_administration_utility
netapp/steelstore_cloud_integrated_storage
Published Feb 26, 2019
Tracked Since Feb 18, 2026