CVE-2019-9169

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
26/02/2019
Last modified:
07/11/2023

Description

In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-insensitive regular-expression match.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:* 2.29 (including)
cpe:2.3:a:netapp:cloud_backup:*:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:steelstore_cloud_integrated_storage:-:*:*:*:*:*:*:*
cpe:2.3:a:mcafee:web_gateway:*:*:*:*:*:*:*:* 7.7.2.0 (including) 7.7.2.21 (excluding)
cpe:2.3:a:mcafee:web_gateway:*:*:*:*:*:*:*:* 7.8.2.0 (including) 7.8.2.8 (excluding)
cpe:2.3:a:mcafee:web_gateway:*:*:*:*:*:*:*:* 8.0.0 (including) 8.1.1 (excluding)
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*