Lucene search

K
ubuntucveUbuntu.comUB:CVE-2014-9402
HistoryFeb 24, 2015 - 12:00 a.m.

CVE-2014-9402

2015-02-2400:00:00
ubuntu.com
ubuntu.com
14

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

0.107 Low

EPSS

Percentile

95.1%

The nss_dns implementation of getnetbyname in GNU C Library (aka glibc)
before 2.21, when the DNS backend in the Name Service Switch configuration
is enabled, allows remote attackers to cause a denial of service (infinite
loop) by sending a positive answer while a network name is being process.

Bugs

Notes

Author Note
mdeslaur fixed by any/cvs-getnetbyname.diff in vivid
OSVersionArchitecturePackageVersionFilename
ubuntu10.04noarcheglibc< 2.11.1-0ubuntu7.21UNKNOWN
ubuntu12.04noarcheglibc< 2.15-0ubuntu10.11UNKNOWN
ubuntu14.04noarcheglibc< 2.19-0ubuntu6.6UNKNOWN
ubuntu14.10noarchglibc< 2.19-10ubuntu2.3UNKNOWN

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

0.107 Low

EPSS

Percentile

95.1%