Vulnerability Description
In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-insensitive regular-expression match.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Glibc | <= 2.29 |
| Netapp | Cloud Backup | All versions |
| Netapp | Ontap Select Deploy Administration Utility | - |
| Netapp | Steelstore Cloud Integrated Storage | - |
| Mcafee | Web Gateway | >= 7.7.2.0, < 7.7.2.21 |
| Canonical | Ubuntu Linux | 16.04 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/107160Broken Link
- https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34140ExploitMailing ListVendor Advisory
- https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34142ExploitMailing ListVendor Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10278Third Party Advisory
- https://security.gentoo.org/glsa/202006-04Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190315-0002/PatchThird Party Advisory
- https://sourceware.org/bugzilla/show_bug.cgi?id=24114Issue TrackingPatchThird Party Advisory
- https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commit%3Bh=583dd860d5b8330
- https://support.f5.com/csp/article/K54823184Third Party Advisory
- https://usn.ubuntu.com/4416-1/Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlNot Applicable
- http://www.securityfocus.com/bid/107160Broken Link
- https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34140ExploitMailing ListVendor Advisory
- https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34142ExploitMailing ListVendor Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10278Third Party Advisory
FAQ
What is CVE-2019-9169?
CVE-2019-9169 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-insensitive regular-expression match.
How severe is CVE-2019-9169?
CVE-2019-9169 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-9169?
Check the references section above for vendor advisories and patch information. Affected products include: Gnu Glibc, Netapp Cloud Backup, Netapp Ontap Select Deploy Administration Utility, Netapp Steelstore Cloud Integrated Storage, Mcafee Web Gateway.