PT-2017-4268 · Gnu+5 · Gnu C Library+5

Florian Weimer

·

Published

2017-04-07

·

Updated

2024-06-15

·

CVE-2017-12132

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions GNU C Library versions prior to 2.26
Description The issue is related to the DNS stub resolver in the GNU C Library. When EDNS support is enabled, it can solicit large UDP responses from name servers, potentially simplifying off-path DNS spoofing attacks due to IP fragmentation. Additionally, there is a memory allocation issue that can be exploited by a remote attacker to impact data integrity.
Recommendations For versions prior to 2.26, update to version 2.26 or later to resolve the issue. As a temporary workaround, consider disabling EDNS support until a patch is available. Restrict access to the DNS stub resolver to minimize the risk of exploitation. Avoid using the affected DNS stub resolver in the GNU C Library until the issue is resolved.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2833
BDU:2023-07723
CESA-2018_0805
CVE-2017-12132
MGASA-2017-0464
MGASA-2017-0470
OPENSUSE-SU-2018_0494-1
OPENSUSE-SU-2024:10792-1
RHSA-2018:0805
RHSA-2018_0805
SUSE-SU-2018:0451-1
SUSE-SU-2018:0565-1
SUSE-SU-2018:2185-1
SUSE-SU-2018:2187-1
SUSE-SU-2018_2185-1
USN-5768-1

Affected Products

Alt Linux
Centos
Gnu C Library
Red Hat
Suse
Ubuntu