Логотип exploitDog
bind:CVE-2021-43523
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-43523

Количество 6

Количество 6

ubuntu логотип

CVE-2021-43523

около 4 лет назад

In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names returned by DNS servers via gethostbyname, getaddrinfo, gethostbyaddr, and getnameinfo can lead to output of wrong hostnames (leading to domain hijacking) or injection into applications (leading to remote code execution, XSS, applications crashes, etc.). In other words, a validation step, which is expected in any stub resolver, does not occur.

CVSS3: 9.6
EPSS: Низкий
nvd логотип

CVE-2021-43523

около 4 лет назад

In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names returned by DNS servers via gethostbyname, getaddrinfo, gethostbyaddr, and getnameinfo can lead to output of wrong hostnames (leading to domain hijacking) or injection into applications (leading to remote code execution, XSS, applications crashes, etc.). In other words, a validation step, which is expected in any stub resolver, does not occur.

CVSS3: 9.6
EPSS: Низкий
msrc логотип

CVE-2021-43523

около 4 лет назад

In uClibc and uClibc-ng before 1.0.39 incorrect handling of special characters in domain names returned by DNS servers via gethostbyname getaddrinfo gethostbyaddr and getnameinfo can lead to output of wrong hostnames (leading to domain hijacking) or injection into applications (leading to remote code execution XSS applications crashes etc.). In other words a validation step which is expected in any stub resolver does not occur.

CVSS3: 9.6
EPSS: Низкий
debian логотип

CVE-2021-43523

около 4 лет назад

In uClibc and uClibc-ng before 1.0.39, incorrect handling of special c ...

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-65xv-vmv6-8r3f

больше 3 лет назад

In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names returned by DNS servers via gethostbyname, getaddrinfo, gethostbyaddr, and getnameinfo can lead to output of wrong hostnames (leading to domain hijacking) or injection into applications (leading to remote code execution, XSS, applications crashes, etc.). In other words, a validation step, which is expected in any stub resolver, does not occur.

CVSS3: 9.6
EPSS: Низкий
fstec логотип

BDU:2023-04414

около 4 лет назад

Уязвимость библиотек uClibC и uClibC-ng промышленных межсетевых экранов Hirschmann EAGLE, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-43523

In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names returned by DNS servers via gethostbyname, getaddrinfo, gethostbyaddr, and getnameinfo can lead to output of wrong hostnames (leading to domain hijacking) or injection into applications (leading to remote code execution, XSS, applications crashes, etc.). In other words, a validation step, which is expected in any stub resolver, does not occur.

CVSS3: 9.6
3%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-43523

In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names returned by DNS servers via gethostbyname, getaddrinfo, gethostbyaddr, and getnameinfo can lead to output of wrong hostnames (leading to domain hijacking) or injection into applications (leading to remote code execution, XSS, applications crashes, etc.). In other words, a validation step, which is expected in any stub resolver, does not occur.

CVSS3: 9.6
3%
Низкий
около 4 лет назад
msrc логотип
CVE-2021-43523

In uClibc and uClibc-ng before 1.0.39 incorrect handling of special characters in domain names returned by DNS servers via gethostbyname getaddrinfo gethostbyaddr and getnameinfo can lead to output of wrong hostnames (leading to domain hijacking) or injection into applications (leading to remote code execution XSS applications crashes etc.). In other words a validation step which is expected in any stub resolver does not occur.

CVSS3: 9.6
3%
Низкий
около 4 лет назад
debian логотип
CVE-2021-43523

In uClibc and uClibc-ng before 1.0.39, incorrect handling of special c ...

CVSS3: 9.6
3%
Низкий
около 4 лет назад
github логотип
GHSA-65xv-vmv6-8r3f

In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names returned by DNS servers via gethostbyname, getaddrinfo, gethostbyaddr, and getnameinfo can lead to output of wrong hostnames (leading to domain hijacking) or injection into applications (leading to remote code execution, XSS, applications crashes, etc.). In other words, a validation step, which is expected in any stub resolver, does not occur.

CVSS3: 9.6
3%
Низкий
больше 3 лет назад
fstec логотип
BDU:2023-04414

Уязвимость библиотек uClibC и uClibC-ng промышленных межсетевых экранов Hirschmann EAGLE, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.6
3%
Низкий
около 4 лет назад

Уязвимостей на страницу