Vulnerability CVE-2016-3075: Information
Description
Stack-based buffer overflow in the nss_dns implementation of the getnetbyname function in GNU C Library (aka glibc) before 2.24 allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a long name.
Severity: HIGH (7.5) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
glibc | sisyphus | 2.23-alt2 | 2.38.0.76.e9f05fa1c6-alt1 | ALT-PU-2016-1480-1 | 164298 | Fixed |
glibc | p10 | 2.23-alt2 | 2.32-alt5.p10.2 | ALT-PU-2016-1480-1 | 164298 | Fixed |
glibc | p9 | 2.23-alt2 | 2.27-alt14 | ALT-PU-2016-1480-1 | 164298 | Fixed |
glibc | p8 | 2.23-alt2 | 2.23-alt3.M80P.2 | ALT-PU-2016-1514-1 | 164761 | Fixed |
glibc | c10f1 | 2.23-alt2 | 2.32-alt5.p10.2 | ALT-PU-2016-1480-1 | 164298 | Fixed |
glibc | c9f2 | 2.23-alt2 | 2.27-alt14 | ALT-PU-2016-1480-1 | 164298 | Fixed |
glibc | c7 | 2.17-alt5.M70C.12 | 2.17-alt5.M70C.14 | ALT-PU-2016-2029-1 | 169527 | Fixed |