MEDIUM · 6.8

CVE-2015-2305

Integer overflow in the regcomp implementation in the Henry Spencer BSD regex library (aka rxspencer) alpha3.8.g5 on 32-bit platforms, as used in NetBSD through 6.1.5 and other products, might allow c...

Vulnerability Description

Integer overflow in the regcomp implementation in the Henry Spencer BSD regex library (aka rxspencer) alpha3.8.g5 on 32-bit platforms, as used in NetBSD through 6.1.5 and other products, might allow context-dependent attackers to execute arbitrary code via a large regular expression that leads to a heap-based buffer overflow.

CVSS Score

6.8

MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
Rxspencer ProjectRxspencer3.8.g5
CanonicalUbuntu Linux10.04
DebianDebian Linux7.0
OpensuseOpensuse13.1
PhpPhp>= 5.4.0, < 5.4.39

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-2305?

CVE-2015-2305 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Integer overflow in the regcomp implementation in the Henry Spencer BSD regex library (aka rxspencer) alpha3.8.g5 on 32-bit platforms, as used in NetBSD through 6.1.5 and other products, might allow c...

How severe is CVE-2015-2305?

CVE-2015-2305 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-2305?

Check the references section above for vendor advisories and patch information. Affected products include: Rxspencer Project Rxspencer, Canonical Ubuntu Linux, Debian Debian Linux, Opensuse Opensuse, Php Php.