In the GNU C Library (aka glibc or libc6) before 2.28, parse_reg_exp in posix/regcomp.c misparses alternatives, which allows attackers to cause a denial of service (assertion failure and application exit) or trigger an incorrect result by attempting a regular-expression match.
                
            Metrics
Affected Vendors & Products
References
        History
                    Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        
        epss
         
  | 
    
        
        
        epss
         
  | 
Status: PUBLISHED
Assigner: mitre
Published: 2019-02-26T02:00:00
Updated: 2024-08-07T07:32:23.298Z
Reserved: 2019-02-25T00:00:00
Link: CVE-2009-5155
No data.
Status : Modified
Published: 2019-02-26T02:29:00.277
Modified: 2024-11-21T01:11:17.400
Link: CVE-2009-5155