Upstream information

CVE-2015-5277 at MITRE

Description

The get_contents function in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) before 2.20 might allow local users to cause a denial of service (heap corruption) or gain privileges via a long line in the NSS files database.

SUSE information

Overall state of this security issue: Resolved

This issue is currently not rated by SUSE as it is not affecting the SUSE Enterprise products.

CVSS v2 Scores
CVSS detail National Vulnerability Database
Base Score 7.2
Vector AV:L/AC:L/Au:N/C:C/I:C/A:C
Access Vector Local
Access Complexity Low
Authentication None
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete
SUSE Bugzilla entries: 1123874 [NEW], 945830 [RESOLVED / DUPLICATE]

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
SUSE Liberty Linux 7
  • glibc >= 2.17-106.el7_2.1
  • glibc-common >= 2.17-106.el7_2.1
  • glibc-devel >= 2.17-106.el7_2.1
  • glibc-headers >= 2.17-106.el7_2.1
  • glibc-static >= 2.17-106.el7_2.1
  • glibc-utils >= 2.17-106.el7_2.1
  • nscd >= 2.17-106.el7_2.1
Patchnames:
RHSA-2015:2172


SUSE Timeline for this CVE

CVE page created: Mon Sep 14 18:15:48 2015
CVE page last modified: Fri May 8 14:26:53 2026