CVE-2015-5229
Last modified
CVE-2015-5229 is a vulnerability of currently unknown severity. The calloc function in the glibc package in Red Hat Enterprise Linux (RHEL) 6.7 and 7.2 does not properly initialize memory areas, which might allow context-dependent attackers to cause a denial of service (hang or crash) via unspecified vectors.. EPSS estimates a 2.20% chance of exploitation in the next 30 days.
Description
The calloc function in the glibc package in Red Hat Enterprise Linux (RHEL) 6.7 and 7.2 does not properly initialize memory areas, which might allow context-dependent attackers to cause a denial of service (hang or crash) via unspecified vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Enterprise Linux | 6.7 |
| Redhat | Enterprise Linux | 7.2 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Hpc Node | 7.0 |
| Redhat | Enterprise Linux Hpc Node Eus | 7.2 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Server Aus | 7.2 |
| Redhat | Enterprise Linux Server Eus | 7.2 |
| Redhat | Enterprise Linux Workstation | 7.0 |
References
- http://rhn.redhat.com/errata/RHSA-2016-0176.htmlVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1246713Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1256285Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1293976Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0176.htmlVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1246713Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1256285Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1293976Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-5229?
How severe is CVE-2015-5229?
How do I fix CVE-2015-5229?
Are you affected by CVE-2015-5229?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
