Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ian Lance Taylor

#21121of 53,633
11.8Total CVSS
Vulnerabilities · 2
Medium
2
PT-2019-4695
6.8
2019-11-28
Linux · Linux Kernel · CVE-2019-19602
**Name of the Vulnerable Software and Affected Versions** Linux kernel versions prior to 5.4.2 **Description** The issue is related to the `fpregs state valid` function in the Linux kernel, which can be exploited by context-dependent attackers to cause a denial of service or possibly have other unspecified impacts due to incorrect caching. This is demonstrated by the mishandling of signal-based non-cooperative preemption in certain environments. The vulnerability may also allow an attacker to disclose protected information or cause a denial of service, as it is caused by a "race condition" situation. **Recommendations** For Linux kernel versions prior to 5.4.2, update to version 5.4.2 or later to resolve the issue. At the moment, there is no information about additional mitigation measures for this vulnerability.
PT-2015-3583
5.0
2015-02-24
Gnu · Glibc · CVE-2013-7423
**Name of the Vulnerable Software and Affected Versions** glibc versions prior to 2.20 **Description** The issue arises from the send dg function in resolv/res send.c, which fails to properly reuse file descriptors. This allows remote attackers to send DNS queries to unintended locations by triggering a large number of requests that call the getaddrinfo function. **Recommendations** For versions prior to 2.20, update to version 2.20 or later to resolve the issue.