Vulnerability Name: | CVE-2018-19591 (CCN-153536) | ||||||||||||||||||||||||||||||||||||||||||||
Assigned: | 2018-11-27 | ||||||||||||||||||||||||||||||||||||||||||||
Published: | 2018-11-27 | ||||||||||||||||||||||||||||||||||||||||||||
Updated: | 2020-07-09 | ||||||||||||||||||||||||||||||||||||||||||||
Summary: | In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to the if_nametoindex() function. | ||||||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-20 | ||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2018-19591 Source: CCN Type: IBM Security Bulletin 878597 (Security 1G Network Active Bypass) IBM Security Proventia Network Active Bypass is affected by glibc vulnerabilities (CVE-2018-19591) Source: BID Type: Third Party Advisory, VDB Entry 106037 Source: SECTRACK Type: Third Party Advisory, VDB Entry 1042174 Source: XF Type: UNKNOWN glibc-cve201819591-dos(153536) Source: FEDORA Type: Third Party Advisory FEDORA-2018-f6b7df660d Source: FEDORA Type: Patch, Third Party Advisory FEDORA-2018-060302dc83 Source: CCN Type: oss-sec Mailing List, Thu, 27 Nov 2018 14:45:05 +0530 (IST) CVE-2018-19591: glibc if_nametoindex may not close descriptor Source: GENTOO Type: Third Party Advisory GLSA-201903-09 Source: GENTOO Type: UNKNOWN GLSA-201908-06 Source: CONFIRM Type: UNKNOWN https://security.netapp.com/advisory/ntap-20190321-0003/ Source: CCN Type: Sourceware Bugzilla Bug 23927 (CVE-2018-19591) - Linux if_nametoindex() does not close descriptor Source: CONFIRM Type: Exploit, Issue Tracking, Third Party Advisory https://sourceware.org/bugzilla/show_bug.cgi?id=23927 Source: CONFIRM Type: Release Notes, Third Party Advisory https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=NEWS;hb=HEAD Source: CONFIRM Type: Mailing List, Patch, Third Party Advisory https://sourceware.org/git/gitweb.cgi?p=glibc.git;a=commitdiff;h=d527c860f5a3f0ed687bd03f0cb464612dc23408 Source: UBUNTU Type: UNKNOWN USN-4416-1 Source: CCN Type: glibc Web site The GNU C Library (glibc) Source: CCN Type: IBM Security Bulletin 1143466 (Watson Studio Local) Multiple Vulnerabilities in GNU C Library affects IBM Watson Studio Local Source: CCN Type: IBM Security Bulletin 6982841 (Netcool Operations Insight) Netcool Operations Insight v1.6.8 addresses multiple security vulnerabilities. | ||||||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||
BACK |