CVE-2014-3484 — Out-of-bounds Write in Musl
Severity
9.8CRITICALNVD
EPSS
1.8%
top 17.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 20
Latest updateMay 17
Description
Multiple stack-based buffer overflows in the __dn_expand function in network/dn_expand.c in musl libc 1.1x before 1.1.2 and 0.9.13 through 1.0.3 allow remote attackers to (1) have unspecified impact via an invalid name length in a DNS response or (2) cause a denial of service (crash) via an invalid name length in a DNS response, related to an infinite loop with no output.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages2 packages
Patches
🔴Vulnerability Details
4GHSA▶
GHSA-j83j-g9hw-7wvp: Multiple stack-based buffer overflows in the __dn_expand function in network/dn_expand↗2022-05-17
CVEList▶
CVE-2014-3484: Multiple stack-based buffer overflows in the __dn_expand function in network/dn_expand↗2020-02-20
OSV▶
CVE-2014-3484: Multiple stack-based buffer overflows in the __dn_expand function in network/dn_expand↗2020-02-20