CVE-2014-9402Infinite Loop in Glibc

Severity
7.8HIGHNVD
EPSS
8.7%
top 7.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 24
Latest updateMay 14

Description

The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2.21, when the DNS backend in the Name Service Switch configuration is enabled, allows remote attackers to cause a denial of service (infinite loop) by sending a positive answer while a network name is being process.

CVSS vector

AV:N/AC:L/C:N/I:N/A:CExploitability: 10.0 | Impact: 6.9

Affected Packages3 packages

Debiangnu/glibc< 2.19-14+3
NVDgnu/glibc2.20
NVDopensuse/opensuse13.1, 13.2+1

Also affects: Ubuntu Linux 10.04, 12.04, 14.04, 14.10

🔴Vulnerability Details

4
GHSA
GHSA-9rf5-3j57-32x7: The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 22022-05-14
OSV
eglibc, glibc vulnerabilities2015-02-26
CVEList
CVE-2014-9402: The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 22015-02-24
OSV
CVE-2014-9402: The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 22015-02-24

📋Vendor Advisories

3
Ubuntu
GNU C Library vulnerabilities2015-02-26
Red Hat
glibc: denial of service in getnetbyname function2014-11-20
Debian
CVE-2014-9402: glibc - The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2...2014

💬Community

1
Bugzilla
CVE-2014-9402 glibc: denial of service in getnetbyname function2014-12-17
CVE-2014-9402 — Infinite Loop in GNU Glibc | cvebase