// For flags

CVE-2023-4527

Glibc: stack read overflow in getaddrinfo in no-aaaa mode

Severity Score

6.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash.

Se encontró una falla en glibc. Cuando se llama a la función getaddrinfo con la familia de direcciones AF_UNSPEC y el sistema está configurado con el modo no-aaaa a través de /etc/resolv.conf, una respuesta DNS a través de TCP de más de 2048 bytes puede potencialmente revelar el contenido de la pila de memoria a través de los datos de la dirección devuelta por la función, y puede provocar un crash.

*Credits: This issue was discovered by Florian Weimer (Red Hat).
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2023-08-24 CVE Reserved
  • 2023-09-18 CVE Published
  • 2024-09-16 CVE Updated
  • 2024-09-16 First Exploit
  • 2024-09-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-121: Stack-based Buffer Overflow
  • CWE-125: Out-of-bounds Read
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Netapp
Search vendor "Netapp"
H300s Firmware
Search vendor "Netapp" for product "H300s Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
H300s
Search vendor "Netapp" for product "H300s"
--
Safe
Netapp
Search vendor "Netapp"
H500s Firmware
Search vendor "Netapp" for product "H500s Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
H500s
Search vendor "Netapp" for product "H500s"
--
Safe
Netapp
Search vendor "Netapp"
H700s Firmware
Search vendor "Netapp" for product "H700s Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
H700s
Search vendor "Netapp" for product "H700s"
--
Safe
Netapp
Search vendor "Netapp"
H410s Firmware
Search vendor "Netapp" for product "H410s Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
H410s
Search vendor "Netapp" for product "H410s"
--
Safe
Netapp
Search vendor "Netapp"
H410c Firmware
Search vendor "Netapp" for product "H410c Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
H410c
Search vendor "Netapp" for product "H410c"
--
Safe
Gnu
Search vendor "Gnu"
Glibc
Search vendor "Gnu" for product "Glibc"
< 2.39
Search vendor "Gnu" for product "Glibc" and version " < 2.39"
-
Affected
Redhat
Search vendor "Redhat"
Codeready Linux Builder Eus
Search vendor "Redhat" for product "Codeready Linux Builder Eus"
9.2
Search vendor "Redhat" for product "Codeready Linux Builder Eus" and version "9.2"
-
Affected
Redhat
Search vendor "Redhat"
Codeready Linux Builder Eus For Power Little Endian
Search vendor "Redhat" for product "Codeready Linux Builder Eus For Power Little Endian"
9.0_ppc64le
Search vendor "Redhat" for product "Codeready Linux Builder Eus For Power Little Endian" and version "9.0_ppc64le"
-
Affected
Redhat
Search vendor "Redhat"
Codeready Linux Builder Eus For Power Little Endian Eus
Search vendor "Redhat" for product "Codeready Linux Builder Eus For Power Little Endian Eus"
9.2_ppc64le
Search vendor "Redhat" for product "Codeready Linux Builder Eus For Power Little Endian Eus" and version "9.2_ppc64le"
-
Affected
Redhat
Search vendor "Redhat"
Codeready Linux Builder For Arm64
Search vendor "Redhat" for product "Codeready Linux Builder For Arm64"
9.0_aarch64
Search vendor "Redhat" for product "Codeready Linux Builder For Arm64" and version "9.0_aarch64"
-
Affected
Redhat
Search vendor "Redhat"
Codeready Linux Builder For Arm64 Eus
Search vendor "Redhat" for product "Codeready Linux Builder For Arm64 Eus"
9.2_aarch64
Search vendor "Redhat" for product "Codeready Linux Builder For Arm64 Eus" and version "9.2_aarch64"
-
Affected
Redhat
Search vendor "Redhat"
Codeready Linux Builder For Ibm Z Systems
Search vendor "Redhat" for product "Codeready Linux Builder For Ibm Z Systems"
9.0_s390x
Search vendor "Redhat" for product "Codeready Linux Builder For Ibm Z Systems" and version "9.0_s390x"
-
Affected
Redhat
Search vendor "Redhat"
Codeready Linux Builder For Ibm Z Systems Eus
Search vendor "Redhat" for product "Codeready Linux Builder For Ibm Z Systems Eus"
9.2_s390x
Search vendor "Redhat" for product "Codeready Linux Builder For Ibm Z Systems Eus" and version "9.2_s390x"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
8.0
Search vendor "Redhat" for product "Enterprise Linux" and version "8.0"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
9.0
Search vendor "Redhat" for product "Enterprise Linux" and version "9.0"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux Eus
Search vendor "Redhat" for product "Enterprise Linux Eus"
8.8
Search vendor "Redhat" for product "Enterprise Linux Eus" and version "8.8"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux Eus
Search vendor "Redhat" for product "Enterprise Linux Eus"
9.2
Search vendor "Redhat" for product "Enterprise Linux Eus" and version "9.2"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux For Arm 64
Search vendor "Redhat" for product "Enterprise Linux For Arm 64"
9.0_aarch64
Search vendor "Redhat" for product "Enterprise Linux For Arm 64" and version "9.0_aarch64"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux For Arm 64 Eus
Search vendor "Redhat" for product "Enterprise Linux For Arm 64 Eus"
9.2_aarch64
Search vendor "Redhat" for product "Enterprise Linux For Arm 64 Eus" and version "9.2_aarch64"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux For Ibm Z Systems
Search vendor "Redhat" for product "Enterprise Linux For Ibm Z Systems"
8.0_s390x
Search vendor "Redhat" for product "Enterprise Linux For Ibm Z Systems" and version "8.0_s390x"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux For Ibm Z Systems Eus
Search vendor "Redhat" for product "Enterprise Linux For Ibm Z Systems Eus"
8.8_s390x
Search vendor "Redhat" for product "Enterprise Linux For Ibm Z Systems Eus" and version "8.8_s390x"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux For Ibm Z Systems Eus S390x
Search vendor "Redhat" for product "Enterprise Linux For Ibm Z Systems Eus S390x"
9.2
Search vendor "Redhat" for product "Enterprise Linux For Ibm Z Systems Eus S390x" and version "9.2"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux For Ibm Z Systems S390x
Search vendor "Redhat" for product "Enterprise Linux For Ibm Z Systems S390x"
9.2
Search vendor "Redhat" for product "Enterprise Linux For Ibm Z Systems S390x" and version "9.2"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux For Power Little Endian
Search vendor "Redhat" for product "Enterprise Linux For Power Little Endian"
8.0_ppc64le
Search vendor "Redhat" for product "Enterprise Linux For Power Little Endian" and version "8.0_ppc64le"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux For Power Little Endian
Search vendor "Redhat" for product "Enterprise Linux For Power Little Endian"
9.2_ppc64le
Search vendor "Redhat" for product "Enterprise Linux For Power Little Endian" and version "9.2_ppc64le"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux For Power Little Endian Eus
Search vendor "Redhat" for product "Enterprise Linux For Power Little Endian Eus"
8.8_ppc64le
Search vendor "Redhat" for product "Enterprise Linux For Power Little Endian Eus" and version "8.8_ppc64le"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux For Power Little Endian Eus
Search vendor "Redhat" for product "Enterprise Linux For Power Little Endian Eus"
9.2_ppc64le
Search vendor "Redhat" for product "Enterprise Linux For Power Little Endian Eus" and version "9.2_ppc64le"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux Server Aus
Search vendor "Redhat" for product "Enterprise Linux Server Aus"
9.2
Search vendor "Redhat" for product "Enterprise Linux Server Aus" and version "9.2"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions
Search vendor "Redhat" for product "Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions"
9.2_ppc64le
Search vendor "Redhat" for product "Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions" and version "9.2_ppc64le"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux Tus
Search vendor "Redhat" for product "Enterprise Linux Tus"
8.8
Search vendor "Redhat" for product "Enterprise Linux Tus" and version "8.8"
-
Affected
Fedoraproject
Search vendor "Fedoraproject"
Fedora
Search vendor "Fedoraproject" for product "Fedora"
37
Search vendor "Fedoraproject" for product "Fedora" and version "37"
-
Affected
Fedoraproject
Search vendor "Fedoraproject"
Fedora
Search vendor "Fedoraproject" for product "Fedora"
38
Search vendor "Fedoraproject" for product "Fedora" and version "38"
-
Affected
Fedoraproject
Search vendor "Fedoraproject"
Fedora
Search vendor "Fedoraproject" for product "Fedora"
39
Search vendor "Fedoraproject" for product "Fedora" and version "39"
-
Affected