Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-4813

Опубликовано: 01 мар. 2022
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

A flaw was found in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or SUCCESS=merge.

Отчет

This issue is only exploitable when the condition detailed in the description is present in the system. However, all glibc versions shipped in Red Hat Enterprise Linux are vulnerable to this issue.

Меры по смягчению последствий

Removing the "SUCCESS=continue" or "SUCCESS=merge" configuration from the hosts database in /etc/nsswitch.conf will mitigate this vulnerability. Note that, these options are not supported by the hosts database, if they were working before it was because of this bug.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6compat-glibcOut of support scope
Red Hat Enterprise Linux 6glibcOut of support scope
Red Hat Enterprise Linux 7compat-glibcWill not fix
Red Hat Enterprise Linux 7glibcWill not fix
Red Hat Enterprise Linux 8glibcFixedRHSA-2023:545505.10.2023
Red Hat Enterprise Linux 8glibcFixedRHSA-2023:545505.10.2023
Red Hat Enterprise Linux 8.6 Extended Update SupportglibcFixedRHSA-2023:740921.11.2023
Red Hat Enterprise Linux 9glibcFixedRHBA-2024:241330.04.2024
Red Hat Enterprise Linux 9glibcFixedRHSA-2023:545305.10.2023
Red Hat Enterprise Linux 9glibcFixedRHBA-2024:241330.04.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2237798glibc: potential use-after-free in gaih_inet()

EPSS

Процентиль: 45%
0.00226
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
почти 2 года назад

A flaw was found in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or SUCCESS=merge.

CVSS3: 5.9
nvd
почти 2 года назад

A flaw was found in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or SUCCESS=merge.

CVSS3: 5.9
debian
почти 2 года назад

A flaw was found in glibc. In an uncommon situation, the gaih_inet fun ...

suse-cvrf
больше 1 года назад

Security update for glibc

suse-cvrf
больше 1 года назад

Security update for glibc

EPSS

Процентиль: 45%
0.00226
Низкий

5.9 Medium

CVSS3