Vulnerability Name: | CVE-2017-15650 (CCN-133862) | ||||||||||||||||||||||||||||||||||||||||
Assigned: | 2017-10-19 | ||||||||||||||||||||||||||||||||||||||||
Published: | 2017-10-19 | ||||||||||||||||||||||||||||||||||||||||
Updated: | 2017-11-08 | ||||||||||||||||||||||||||||||||||||||||
Summary: | musl libc before 1.1.17 has a buffer overflow via crafted DNS replies because dns_parse_callback in network/lookup_name.c does not restrict the number of addresses, and thus an attacker can provide an unexpected number by sending A records in a reply to an AAAA query. | ||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
6.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-119 | ||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-15650 Source: CONFIRM Type: Vendor Advisory http://git.musl-libc.org/cgit/musl/commit/?id=45ca5d3fcb6f874bf5ba55d0e9651cef68515395 Source: CONFIRM Type: Vendor Advisory http://git.musl-libc.org/cgit/musl/tree/WHATSNEW Source: CCN Type: oss-sec Mailing List, Thu, 19 Oct 2017 16:17:57 -0400 CVE request: musl libc 1.1.16 and earlier dns buffer overflow Source: CONFIRM Type: Mailing List, Mitigation, Third Party Advisory http://openwall.com/lists/oss-security/2017/10/19/5 Source: CCN Type: IBM Security Bulletin 716653 (Cloud Private) Multiple Security Vulnerabilities affect IBM Cloud Private Source: CCN Type: musl libc Web site musl libc Source: XF Type: UNKNOWN musllibc-cve201715650-bo(133862) | ||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||
BACK |