From Moritz Muehlenhoff@21:1/5 to All on Sun Oct 22 12:50:02 2017
XPost: linux.debian.bugs.dist
Package: libc6
Version: 2.24-17
Severity: important
Tags: security
Please see http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15671:
The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27,
when invoked with GLOB_TILDE, could skip freeing allocated memory when processing
the ~ operator with a long user name, potentially leading to a denial of service (memory leak).