Описание
In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters, which could lead applications to incorrectly assume that it had parsed a valid string, without the possibility of embedded HTTP headers or other potentially dangerous substrings.
Релиз | Статус | Примечание |
---|---|---|
bionic | DNE | |
cosmic | DNE | |
devel | DNE | |
disco | DNE | |
eoan | DNE | |
esm-infra-legacy/trusty | needed | |
esm-infra/focal | DNE | |
focal | DNE | |
groovy | DNE | |
hirsute | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | ignored | end of standard support |
cosmic | ignored | end of life |
devel | not-affected | 2.29-0ubuntu2 |
disco | not-affected | 2.29-0ubuntu2 |
eoan | not-affected | 2.29-0ubuntu2 |
esm-infra-legacy/trusty | DNE | |
esm-infra/bionic | ignored | change too intrusive |
esm-infra/focal | not-affected | 2.29-0ubuntu2 |
esm-infra/xenial | ignored | change too intrusive |
focal | not-affected | 2.29-0ubuntu2 |
Показывать по
Ссылки на источники
4.6 Medium
CVSS2
5.3 Medium
CVSS3
Связанные уязвимости
In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters, which could lead applications to incorrectly assume that it had parsed a valid string, without the possibility of embedded HTTP headers or other potentially dangerous substrings.
In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters, which could lead applications to incorrectly assume that it had parsed a valid string, without the possibility of embedded HTTP headers or other potentially dangerous substrings.
In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinf ...
4.6 Medium
CVSS2
5.3 Medium
CVSS3