Unrated severityNVD Advisory· Published Dec 17, 2015· Updated Jun 17, 2026
CVE-2015-5277
CVE-2015-5277
Description
The get_contents function in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) before 2.20 might allow local users to cause a denial of service (heap corruption) or gain privileges via a long line in the NSS files database.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*+ 2 more
- cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_hpc_node:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
12- packetstormsecurity.com/files/154361/Cisco-Device-Hardcoded-Credentials-GNU-glibc-BusyBox.htmlnvd
- rhn.redhat.com/errata/RHSA-2015-2172.htmlnvd
- seclists.org/fulldisclosure/2019/Sep/7nvd
- www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlnvd
- www.securityfocus.com/bid/78092nvd
- www.securitytracker.com/id/1034196nvd
- www.ubuntu.com/usn/USN-2985-1nvd
- www.ubuntu.com/usn/USN-2985-2nvd
- bugzilla.redhat.com/show_bug.cginvd
- seclists.org/bugtraq/2019/Sep/7nvd
- security.gentoo.org/glsa/201702-11nvd
- sourceware.org/bugzilla/show_bug.cginvd
News mentions
0No linked articles in our index yet.