PT-2020-7650 · Musl Libc+1 · Musl Libc+1

Rich Felker

·

Published

2014-06-18

·

Updated

2021-03-15

·

CVE-2014-3484

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions musl libc versions 0.9.13 through 1.0.3 musl libc versions 1.1.x before 1.1.2
Description The issue is related to multiple stack-based buffer overflows in the dn expand function, which can be triggered by an invalid name length in a DNS response. This can allow remote attackers to have an unspecified impact or cause a denial of service (crash), related to an infinite loop with no output.
Recommendations For musl libc versions 0.9.13 through 1.0.3, update to version 1.0.4 or later. For musl libc versions 1.1.x before 1.1.2, update to version 1.1.2 or later. As a temporary workaround, consider restricting the use of the dn expand function in the network/dn expand.c file until a patch is available.

Exploit

Fix

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-3484
MGASA-2014-0262
USN-4768-1

Affected Products

Ubuntu
Musl Libc