Information Exposure Affecting glibc package, versions [0,]


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.15% (52nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-GLIBC-5898490
  • published13 Sept 2023
  • disclosed12 Sept 2023
  • creditFlorian Weimer

Introduced: 12 Sep 2023

CVE-2023-4527  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

There is no fixed version for glibc.

Overview

Affected versions of this package are vulnerable to Information Exposure. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash.

CVSS Scores

version 3.1