CVE-2014-8121

CWE-17CWE-83510 documents8 sources
Severity
5.0MEDIUM
EPSS
3.0%
top 13.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 27
Latest updateMay 14

Description

DB_LOOKUP in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) 2.21 and earlier does not properly check if a file is open, which allows remote attackers to cause a denial of service (infinite loop) by performing a look-up on a database while iterating over it, which triggers the file pointer to be reset.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages4 packages

Also affects: Ubuntu Linux 12.04, 14.04, 15.10

🔴Vulnerability Details

4
GHSA
GHSA-hw66-pxhg-8fx8: DB_LOOKUP in nss_files/files-XXX2022-05-14
OSV
eglibc, glibc vulnerabilities2016-05-25
OSV
CVE-2014-8121: DB_LOOKUP in nss_files/files-XXX2015-03-27
CVEList
CVE-2014-8121: DB_LOOKUP in nss_files/files-XXX2015-03-27

📋Vendor Advisories

3
Ubuntu
GNU C Library vulnerabilities2016-05-25
Red Hat
glibc: Unexpected closing of nss_files databases after lookups causes denial of service2015-02-23
Debian
CVE-2014-8121: glibc - DB_LOOKUP in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Lib...2014

💬Community

2
Bugzilla
CVE-2014-8121 glibc: Unexpected closing of nss_files databases after lookups causes denial of service [fedora-all]2015-02-23
Bugzilla
CVE-2014-8121 glibc: Unexpected closing of nss_files databases after lookups causes denial of service2014-11-18
CVE-2014-8121 (MEDIUM CVSS 5) | DB_LOOKUP in nss_files/files-XXX.c | cvebase.io