Vulnerability Description
Buffer overflow in text-utils/colcrt.c in colcrt in util-linux before 2.27 allows local users to cause a denial of service (crash) via a crafted file, related to the page global variable.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kernel | Util-Linux | <= 2.22 |
| Opensuse | Opensuse | 13.1 |
| Opensuse Project | Leap | 42.1 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-updates/2015-11/msg00035.htmlThird Party Advisory
- http://www.spinics.net/lists/util-linux-ng/msg11873.htmlExploit
- https://bugzilla.redhat.com/show_bug.cgi?id=1259322Issue TrackingThird Party Advisory
- https://github.com/kerolasa/lelux-utiliteetit/commit/70e3fcf293c1827a2655a86584aIssue TrackingPatchThird Party Advisory
- https://github.com/kerolasa/lelux-utiliteetit/commit/d883d64d96ab9bef510745d064aIssue TrackingPatchThird Party Advisory
- https://www.kernel.org/pub/linux/utils/util-linux/v2.27/v2.27-ReleaseNotesRelease NotesVendor Advisory
- http://lists.opensuse.org/opensuse-updates/2015-11/msg00035.htmlThird Party Advisory
- http://www.spinics.net/lists/util-linux-ng/msg11873.htmlExploit
- https://bugzilla.redhat.com/show_bug.cgi?id=1259322Issue TrackingThird Party Advisory
- https://github.com/kerolasa/lelux-utiliteetit/commit/70e3fcf293c1827a2655a86584aIssue TrackingPatchThird Party Advisory
- https://github.com/kerolasa/lelux-utiliteetit/commit/d883d64d96ab9bef510745d064aIssue TrackingPatchThird Party Advisory
- https://www.kernel.org/pub/linux/utils/util-linux/v2.27/v2.27-ReleaseNotesRelease NotesVendor Advisory
FAQ
What is CVE-2015-5218?
CVE-2015-5218 is a vulnerability with a CVSS score of 2.1 (LOW). Buffer overflow in text-utils/colcrt.c in colcrt in util-linux before 2.27 allows local users to cause a denial of service (crash) via a crafted file, related to the page global variable.
How severe is CVE-2015-5218?
CVE-2015-5218 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-5218?
Check the references section above for vendor advisories and patch information. Affected products include: Kernel Util-Linux, Opensuse Opensuse, Opensuse Project Leap.