Lucene search

K
osvGoogleOSV:USN-4768-1
HistoryMar 15, 2021 - 8:10 p.m.

musl vulnerabilities

2021-03-1520:10:13
Google
osv.dev
6

7.9 High

AI Score

Confidence

High

0.009 Low

EPSS

Percentile

82.7%

It was discovered that musl did not properly handle kernel syscalls. An
attacker could use this vulnerability to cause a denial of service (crash)
or possibly execute arbitrary code. (CVE-2018-1000001)

It was discovered that musl did not properly handle the parsing of DNS
response codes. A remote attacker could use this vulnerability to cause
resource consumption (infinite loop), denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 14.04 ESM.
(CVE-2014-3484)

It was discovered that musl did not properly handle the parsing of DNS
response codes. A remote attacker could use this vulnerability to cause
resource consumption (infinite loop), denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 16.04 ESM.
(CVE-2017-15650)

It was discovered that musl did not properly handle the parsing of ipv6
addresses. An attacker could use this vulnerability to cause a denial of
service (crash) or possibly execute arbitrary code. This issue only affected
Ubuntu 14.04 ESM. (CVE-2015-1817)

It was discovered that TRE library, used by musl, did not properly handle
certain inputs. An attacker could use this vulnerability to cause a denial of
service (crash). (CVE-2016-8859)