A stack overflow flaw was found in glibc's swscanf() function. An attacker able to make an application call the swscanf() function could use this flaw to crash that application or, potentially, execute arbitrary code with the permissions of the user running the application.
Platform | Package | Release Date | Advisory |
---|---|---|---|
Amazon Linux 1 | glibc | 2015-12-14 10:00 | ALAS-2015-617 |
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv2 | 2.6 | AV:L/AC:H/Au:N/C:P/I:N/A:P |
NVD | CVSSv2 | 6.4 | AV:N/AC:L/Au:N/C:N/I:P/A:P |