Lucene search

K
f5F5F5:K16365
HistoryJul 23, 2015 - 12:00 a.m.

K16365 : glibc vulnerability CVE-2014-9402

2015-07-2300:00:00
my.f5.com
13

8 High

AI Score

Confidence

High

0.107 Low

EPSS

Percentile

95.1%

Security Advisory Description

The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2.21, when the DNS backend in the Name Service Switch configuration is enabled, allows remote attackers to cause a denial of service (infinite loop) by sending a positive answer while a network name is being process. (CVE-2014-9402)

Impact

This vulnerability can only be exploited if you explicitly enable DNS for networks in the Name Service Switch Configuration file (/etc/nsswitch.conf). By default, the BIG-IP system does not have DNS enabled for networks in the Name Service Switch configuration and is not vulnerable. An attacker with local access and knowledge of how to make theglibc function trigger an exploit may be able to cause a denial of service (DoS).