---
title: "CVE-2015-5218\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2015-5218?format=md
keywords: index, follow
---

# CVE-2015-5218

Publication date 9 November 2015

Last updated 24 July 2024

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Buffer overflow in text-utils/colcrt.c in colcrt in util-linux before 2.27
allows local users to cause a denial of service (crash) via a crafted file,
related to the page global variable.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2015-5218?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| bsdmainutils | 22.04 LTS jammy | Not affected |
| 21.10 impish | Not affected |
| 21.04 hirsute | Ignored end of life |
| 20.10 groovy | Ignored end of life |
| 20.04 LTS focal | Not affected |
| 19.10 eoan | Ignored end of life |
| 19.04 disco | Ignored end of life |
| 18.10 cosmic | Ignored end of life |
| 18.04 LTS bionic | Not affected |
| 17.10 artful | Ignored end of life |
| 17.04 zesty | Ignored end of life |
| 16.10 yakkety | Ignored end of life |
| 16.04 LTS xenial | Not affected |
| 15.10 wily | Ignored end of life |
| 15.04 vivid | Ignored end of life |
| 14.04 LTS trusty | Not affected |
| 12.04 LTS precise | Ignored end of life |
| util-linux | 22.04 LTS jammy | Not affected |
| 21.10 impish | Not affected |
| 21.04 hirsute | Not affected |
| 20.10 groovy | Not affected |
| 20.04 LTS focal | Not affected |
| 19.10 eoan | Not affected |
| 19.04 disco | Not affected |
| 18.10 cosmic | Not affected |
| 18.04 LTS bionic | Not affected |
| 17.10 artful | Not affected |
| 17.04 zesty | Not affected |
| 16.10 yakkety | Not affected |
| 16.04 LTS xenial | Not affected |
| 15.10 wily | Not affected |
| 15.04 vivid | Not affected |
| 14.04 LTS trusty | Not affected |
| 12.04 LTS precise | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2015-5218?format=md#patch-details)

## Notes

---

### [sbeattie](https://launchpad.net/~sbeattie)

fixed in util-linux, but debian/ubuntu util-linux does not
ship colcrt

---

### [ccdm94](https://launchpad.net/~ccdm94)

package bsdmainutils is not vulnerable in any release due to
code that checks for writing beyond array bounds being included in
the commit which introduced multibyte character support (243041573f0).
Releases that include the multibyte character support therefore
include the checks. A fix that identifies read errors was also released
in a 2004 commit (70cd856a0c6), and is present in the code for all
Ubuntu releases that contain colcrt in bsdmainutils. More recent
versions such as Ubuntu 21.10 don't include the colcrt code, as it was
removed from the bsdmainutils source.

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| bsdmainutils | * Upstream:   [usr.bin](https://cgit.freebsd.org/src/commit/usr.bin/colcrt/colcrt.c?h=stable/11&id=70cd856a0c676a8eb2acd677a9627fd1abb92466) |
| util-linux | * Upstream:   [text-ut](http://git.kernel.org/cgit/utils/util-linux/util-linux.git/commit/text-utils/colcrt.c?id=70e3fcf293c1827a2655a86584ab13075124a8a8) * Upstream:   [text-ut](http://git.kernel.org/cgit/utils/util-linux/util-linux.git/commit/text-utils/colcrt.c?id=d883d64d96ab9bef510745d064a351145b9babec) |

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5218)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2015-5218)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2015-5218)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2015-5218)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2015-5218>
