UBUNTU-CVE-2015-2305

See a problem?
Source
https://ubuntu.com/security/notices/UBUNTU-CVE-2015-2305
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2015/UBUNTU-CVE-2015-2305.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2015-2305
Related
Published
2015-03-30T00:00:00Z
Modified
2015-03-30T00:00:00Z
Summary
[none]
Details

Integer overflow in the regcomp implementation in the Henry Spencer BSD regex library (aka rxspencer) alpha3.8.g5 on 32-bit platforms, as used in NetBSD through 6.1.5 and other products, might allow context-dependent attackers to execute arbitrary code via a large regular expression that leads to a heap-based buffer overflow.

References

Affected packages

Ubuntu:14.04:LTS / clamav

Package

Name
clamav
Purl
pkg:deb/ubuntu/clamav@0.98.7+dfsg-0ubuntu0.14.04.1?arch=src?distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.98.7+dfsg-0ubuntu0.14.04.1

Affected versions

0.*

0.97.8+dfsg-1ubuntu4
0.97.8+dfsg-1ubuntu5
0.98.1+dfsg-1ubuntu4
0.98.1+dfsg-1ubuntu5
0.98.1+dfsg-2ubuntu2
0.98.1+dfsg-4ubuntu1
0.98.1+dfsg-4ubuntu1.1
0.98.5+addedllvm-0ubuntu0.14.04.1
0.98.6+dfsg-0ubuntu0.14.04.1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "clamav-docs": "0.98.7+dfsg-0ubuntu0.14.04.1",
            "clamav": "0.98.7+dfsg-0ubuntu0.14.04.1",
            "clamav-testfiles": "0.98.7+dfsg-0ubuntu0.14.04.1",
            "clamav-base": "0.98.7+dfsg-0ubuntu0.14.04.1",
            "clamav-freshclam": "0.98.7+dfsg-0ubuntu0.14.04.1",
            "clamav-milter": "0.98.7+dfsg-0ubuntu0.14.04.1",
            "clamav-daemon": "0.98.7+dfsg-0ubuntu0.14.04.1",
            "libclamav6": "0.98.7+dfsg-0ubuntu0.14.04.1",
            "libclamav-dev": "0.98.7+dfsg-0ubuntu0.14.04.1",
            "clamav-dbg": "0.98.7+dfsg-0ubuntu0.14.04.1"
        }
    ]
}

Ubuntu:14.04:LTS / llvm-toolchain-3.6

Package

Name
llvm-toolchain-3.6
Purl
pkg:deb/ubuntu/llvm-toolchain-3.6@1:3.6-2ubuntu1~trusty2?arch=src?distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:3.6-2ubuntu1~trusty2

Affected versions

1:3.*

1:3.6-2ubuntu1~trusty1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "libllvm-3.6-ocaml-dev": "1:3.6-2ubuntu1~trusty2",
            "clang-3.6": "1:3.6-2ubuntu1~trusty2",
            "python-clang-3.6": "1:3.6-2ubuntu1~trusty2",
            "llvm-3.6-tools": "1:3.6-2ubuntu1~trusty2",
            "lldb-3.6-dev": "1:3.6-2ubuntu1~trusty2",
            "llvm-3.6": "1:3.6-2ubuntu1~trusty2",
            "libclang1-3.6-dbg": "1:3.6-2ubuntu1~trusty2",
            "libllvm3.6-dbg": "1:3.6-2ubuntu1~trusty2",
            "llvm-3.6-dev-dbgsym": "1:3.6-2ubuntu1~trusty2",
            "libclang-3.6-dev": "1:3.6-2ubuntu1~trusty2",
            "libllvm3.6": "1:3.6-2ubuntu1~trusty2",
            "liblldb-3.6": "1:3.6-2ubuntu1~trusty2",
            "python-lldb-3.6": "1:3.6-2ubuntu1~trusty2",
            "clang-3.6-doc": "1:3.6-2ubuntu1~trusty2",
            "llvm-3.6-dev": "1:3.6-2ubuntu1~trusty2",
            "cpp11-migrate-3.6": "1:3.6-2ubuntu1~trusty2",
            "clang-format-3.6": "1:3.6-2ubuntu1~trusty2",
            "libclang1-3.6": "1:3.6-2ubuntu1~trusty2",
            "clang-modernize-3.6": "1:3.6-2ubuntu1~trusty2",
            "clang-3.6-examples": "1:3.6-2ubuntu1~trusty2",
            "libclang-common-3.6-dev": "1:3.6-2ubuntu1~trusty2",
            "llvm-3.6-examples": "1:3.6-2ubuntu1~trusty2",
            "llvm-3.6-doc": "1:3.6-2ubuntu1~trusty2",
            "liblldb-3.6-dev": "1:3.6-2ubuntu1~trusty2",
            "liblldb-3.6-dbgsym": "1:3.6-2ubuntu1~trusty2",
            "lldb-3.6": "1:3.6-2ubuntu1~trusty2",
            "llvm-3.6-runtime": "1:3.6-2ubuntu1~trusty2"
        }
    ]
}

Ubuntu:14.04:LTS / newlib

Package

Name
newlib
Purl
pkg:deb/ubuntu/newlib@2.1.0-3?arch=src?distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.0-3

Affected versions

1.*

1.18.0-6.2ubuntu1

2.*

2.1.0-2

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "libnewlib-dev": "2.1.0-3",
            "libnewlib-arm-none-eabi": "2.1.0-3",
            "newlib-source": "2.1.0-3",
            "libnewlib-doc": "2.1.0-3"
        }
    ]
}

Ubuntu:14.04:LTS / php5

Package

Name
php5
Purl
pkg:deb/ubuntu/php5@5.5.9+dfsg-1ubuntu4.9?arch=src?distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.5.9+dfsg-1ubuntu4.9

Affected versions

5.*

5.5.3+dfsg-1ubuntu2
5.5.3+dfsg-1ubuntu3
5.5.6+dfsg-1ubuntu1
5.5.6+dfsg-1ubuntu2
5.5.8+dfsg-2ubuntu1
5.5.9+dfsg-1ubuntu1
5.5.9+dfsg-1ubuntu2
5.5.9+dfsg-1ubuntu3
5.5.9+dfsg-1ubuntu4
5.5.9+dfsg-1ubuntu4.1
5.5.9+dfsg-1ubuntu4.2
5.5.9+dfsg-1ubuntu4.3
5.5.9+dfsg-1ubuntu4.4
5.5.9+dfsg-1ubuntu4.5
5.5.9+dfsg-1ubuntu4.6
5.5.9+dfsg-1ubuntu4.7

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "php5-gd": "5.5.9+dfsg-1ubuntu4.9",
            "libphp5-embed": "5.5.9+dfsg-1ubuntu4.9",
            "php5-mysqlnd": "5.5.9+dfsg-1ubuntu4.9",
            "php5-dbg": "5.5.9+dfsg-1ubuntu4.9",
            "php-pear": "5.5.9+dfsg-1ubuntu4.9",
            "php5-cli": "5.5.9+dfsg-1ubuntu4.9",
            "php5-fpm": "5.5.9+dfsg-1ubuntu4.9",
            "php5-pspell": "5.5.9+dfsg-1ubuntu4.9",
            "php5-mysql": "5.5.9+dfsg-1ubuntu4.9",
            "php5-curl": "5.5.9+dfsg-1ubuntu4.9",
            "php5-ldap": "5.5.9+dfsg-1ubuntu4.9",
            "php5-pgsql": "5.5.9+dfsg-1ubuntu4.9",
            "php5-xsl": "5.5.9+dfsg-1ubuntu4.9",
            "php5-readline": "5.5.9+dfsg-1ubuntu4.9",
            "php5-common": "5.5.9+dfsg-1ubuntu4.9",
            "php5-enchant": "5.5.9+dfsg-1ubuntu4.9",
            "php5-dev": "5.5.9+dfsg-1ubuntu4.9",
            "libapache2-mod-php5filter": "5.5.9+dfsg-1ubuntu4.9",
            "php5": "5.5.9+dfsg-1ubuntu4.9",
            "php5-sybase": "5.5.9+dfsg-1ubuntu4.9",
            "php5-gmp": "5.5.9+dfsg-1ubuntu4.9",
            "php5-odbc": "5.5.9+dfsg-1ubuntu4.9",
            "php5-cgi": "5.5.9+dfsg-1ubuntu4.9",
            "php5-recode": "5.5.9+dfsg-1ubuntu4.9",
            "libapache2-mod-php5": "5.5.9+dfsg-1ubuntu4.9",
            "php5-snmp": "5.5.9+dfsg-1ubuntu4.9",
            "php5-sqlite": "5.5.9+dfsg-1ubuntu4.9",
            "php5-intl": "5.5.9+dfsg-1ubuntu4.9",
            "php5-xmlrpc": "5.5.9+dfsg-1ubuntu4.9",
            "php5-tidy": "5.5.9+dfsg-1ubuntu4.9"
        }
    ]
}

Ubuntu:14.04:LTS / vigor

Package

Name
vigor
Purl
pkg:deb/ubuntu/vigor@0.016-24build0.14.04.1?arch=src?distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.016-24build0.14.04.1

Affected versions

0.*

0.016-22
0.016-23

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "vigor": "0.016-24build0.14.04.1",
            "vigor-dbgsym": "0.016-24build0.14.04.1"
        }
    ]
}

Ubuntu:16.04:LTS / llvm-toolchain-3.5

Package

Name
llvm-toolchain-3.5
Purl
pkg:deb/ubuntu/llvm-toolchain-3.5@1:3.5.2-2?arch=src?distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:3.5.2-2

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "clang-modernize-3.5": "1:3.5.2-2",
            "libclang1-3.5-dbg": "1:3.5.2-2",
            "llvm-3.5-dev-dbgsym": "1:3.5.2-2",
            "llvm-3.5-tools": "1:3.5.2-2",
            "lldb-3.5-dev": "1:3.5.2-2",
            "libclang1-3.5": "1:3.5.2-2",
            "liblldb-3.5-dev": "1:3.5.2-2",
            "libclang-3.5-dev": "1:3.5.2-2",
            "cpp11-migrate-3.5": "1:3.5.2-2",
            "llvm-3.5-dev": "1:3.5.2-2",
            "clang-format-3.5": "1:3.5.2-2",
            "clang-3.5": "1:3.5.2-2",
            "clang-3.5-doc": "1:3.5.2-2",
            "libllvm-3.5-ocaml-dev": "1:3.5.2-2",
            "lldb-3.5": "1:3.5.2-2",
            "python-lldb-3.5": "1:3.5.2-2",
            "python-clang-3.5": "1:3.5.2-2",
            "libllvm3.5v5": "1:3.5.2-2",
            "libllvm-3.5-ocaml-dev-dbgsym": "1:3.5.2-2",
            "llvm-3.5-examples": "1:3.5.2-2",
            "liblldb-3.5": "1:3.5.2-2",
            "llvm-3.5": "1:3.5.2-2",
            "llvm-3.5-runtime": "1:3.5.2-2",
            "clang-3.5-examples": "1:3.5.2-2",
            "liblldb-3.5-dbgsym": "1:3.5.2-2",
            "libllvm3.5-dbg": "1:3.5.2-2",
            "libclang-common-3.5-dev": "1:3.5.2-2",
            "llvm-3.5-doc": "1:3.5.2-2"
        }
    ]
}

Ubuntu:16.04:LTS / llvm-toolchain-3.6

Package

Name
llvm-toolchain-3.6
Purl
pkg:deb/ubuntu/llvm-toolchain-3.6@1:3.6.2-3ubuntu2?arch=src?distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:3.6.2-3ubuntu2

Affected versions

1:3.*

1:3.6.2-1
1:3.6.2-3
1:3.6.2-3build1
1:3.6.2-3ubuntu1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "python-clang-3.6": "1:3.6.2-3ubuntu2",
            "llvm-3.6-tools": "1:3.6.2-3ubuntu2",
            "llvm-3.6": "1:3.6.2-3ubuntu2",
            "libllvm3.6v5": "1:3.6.2-3ubuntu2",
            "liblldb-3.6": "1:3.6.2-3ubuntu2",
            "python-lldb-3.6": "1:3.6.2-3ubuntu2",
            "llvm-3.6-dev": "1:3.6.2-3ubuntu2",
            "clang-format-3.6": "1:3.6.2-3ubuntu2",
            "clang-3.6-examples": "1:3.6.2-3ubuntu2",
            "libclang1-3.6-dbg": "1:3.6.2-3ubuntu2",
            "llvm-3.6-examples": "1:3.6.2-3ubuntu2",
            "llvm-3.6-doc": "1:3.6.2-3ubuntu2",
            "liblldb-3.6-dev": "1:3.6.2-3ubuntu2",
            "liblldb-3.6-dbgsym": "1:3.6.2-3ubuntu2",
            "libclang-common-3.6-dev": "1:3.6.2-3ubuntu2",
            "libllvm-3.6-ocaml-dev": "1:3.6.2-3ubuntu2",
            "clang-3.6": "1:3.6.2-3ubuntu2",
            "lldb-3.6-dev": "1:3.6.2-3ubuntu2",
            "libllvm3.6-dbg": "1:3.6.2-3ubuntu2",
            "llvm-3.6-dev-dbgsym": "1:3.6.2-3ubuntu2",
            "clang-3.6-doc": "1:3.6.2-3ubuntu2",
            "cpp11-migrate-3.6": "1:3.6.2-3ubuntu2",
            "clang-tidy-3.6": "1:3.6.2-3ubuntu2",
            "libclang1-3.6": "1:3.6.2-3ubuntu2",
            "clang-modernize-3.6": "1:3.6.2-3ubuntu2",
            "llvm-3.6-runtime": "1:3.6.2-3ubuntu2",
            "libclang-3.6-dev": "1:3.6.2-3ubuntu2",
            "lldb-3.6": "1:3.6.2-3ubuntu2"
        }
    ]
}

Ubuntu:16.04:LTS / vigor

Package

Name
vigor
Purl
pkg:deb/ubuntu/vigor@0.016-24?arch=src?distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.016-24

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "vigor": "0.016-24",
            "vigor-dbgsym": "0.016-24"
        }
    ]
}

Ubuntu:Pro:16.04:LTS / nvi

Package

Name
nvi

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.81.6-11
1.81.6-12
1.81.6-12build1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:16.04:LTS / openrpt

Package

Name
openrpt

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.3.10-4

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:16.04:LTS / radare2

Package

Name
radare2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.9.6-3.1ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:18.04:LTS / nvi

Package

Name
nvi
Purl
pkg:deb/ubuntu/nvi@1.81.6-13?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.81.6-13

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "nvi-dbgsym": "1.81.6-13",
            "nvi": "1.81.6-13",
            "nvi-doc": "1.81.6-13"
        }
    ]
}

Ubuntu:18.04:LTS / radare2

Package

Name
radare2
Purl
pkg:deb/ubuntu/radare2@2.3.0+dfsg-2?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.3.0+dfsg-2

Affected versions

1.*

1.6.0+dfsg-1

2.*

2.0.0+dfsg-1
2.1.0+dfsg-1
2.3.0+dfsg-1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "libradare2-2.3-dbgsym": "2.3.0+dfsg-2",
            "libradare2-dev": "2.3.0+dfsg-2",
            "libradare2-2.3": "2.3.0+dfsg-2",
            "libradare2-common": "2.3.0+dfsg-2",
            "radare2-dbgsym": "2.3.0+dfsg-2",
            "radare2": "2.3.0+dfsg-2"
        }
    ]
}

Ubuntu:Pro:18.04:LTS / openrpt

Package

Name
openrpt

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.3.12-2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / radare2

Package

Name
radare2
Purl
pkg:deb/ubuntu/radare2@5.5.0+dfsg-1ubuntu1?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.5.0+dfsg-1ubuntu1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "libradare2-common": "5.5.0+dfsg-1ubuntu1",
            "libradare2-dev": "5.5.0+dfsg-1ubuntu1",
            "libradare2-5.0.0": "5.5.0+dfsg-1ubuntu1",
            "radare2-dbgsym": "5.5.0+dfsg-1ubuntu1",
            "libradare2-5.0.0-dbgsym": "5.5.0+dfsg-1ubuntu1",
            "radare2": "5.5.0+dfsg-1ubuntu1"
        }
    ]
}