Oval Definition:oval:com.ubuntu.trusty:def:20165417000
Revision Date:2017-02-16Version:1
Title:CVE-2016-5417 on Ubuntu 14.04 LTS (trusty) - low.
Description:Memory leak in the __res_vinit function in the IPv6 name server management code in libresolv in GNU C Library (aka glibc or libc6) before 2.24 allows remote attackers to cause a denial of service (memory consumption) by leveraging partial initialization of internal resolver data structures. Tim Ruehsen discovered that the getaddrinfo() implementation in the GNU C Library did not properly track memory allocations. An attacker could use this to cause a denial of service.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2016-5417
Platform(s):Ubuntu 14.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 14.04 LTS (trusty) is installed.
  • AND NOT While related to the CVE in some way, the 'eglibc' package in trusty is not affected (note: 'pre 2.22').
  • BACK