CVE-2021-43523
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names returned by DNS servers via gethostbyname, getaddrinfo, gethostbyaddr, and getnameinfo can lead to output of wrong hostnames (leading to domain hijacking) or injection into applications (leading to remote code execution, XSS, applications crashes, etc.). In other words, a validation step, which is expected in any stub resolver, does not occur.
En uClibc y uClibc-ng versiones anteriores a 1.0.39, el manejo incorrecto de los caracteres especiales en los nombres de dominio devueltos por los servidores DNS por medio de gethostbyname, getaddrinfo, gethostbyaddr y getnameinfo puede conllevar a una salida de nombres de host erróneos (conllevando al secuestro de dominios) o una inyección en aplicaciones (conllevando a una ejecución de código remota, un ataque de tipo XSS, bloqueo de aplicaciones, etc.). En otras palabras, un paso de comprobación, que se espera en cualquier stub resolver, no ocurre
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-11-08 CVE Reserved
- 2021-11-10 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.openwall.com/lists/oss-security/2021/11/09/1 | 2024-08-04 |
URL | Date | SRC |
---|---|---|
https://github.com/wbx-github/uclibc-ng/commit/0f822af0445e5348ce7b7bd8ce1204244f31d174 | 2021-11-15 |
URL | Date | SRC |
---|---|---|
https://uclibc-ng.org | 2021-11-15 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Uclibc Search vendor "Uclibc" | Uclibc Search vendor "Uclibc" for product "Uclibc" | <= 0.9.33.2 Search vendor "Uclibc" for product "Uclibc" and version " <= 0.9.33.2" | - |
Affected
| ||||||
Uclibc-ng Project Search vendor "Uclibc-ng Project" | Uclibc-ng Search vendor "Uclibc-ng Project" for product "Uclibc-ng" | < 1.0.39 Search vendor "Uclibc-ng Project" for product "Uclibc-ng" and version " < 1.0.39" | - |
Affected
|