CVE-2014-9402
published 2015-02-24CVE-2014-9402: The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2.21, when the DNS backend in the Name Service Switch configuration is enabled…
PriorityP340high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
7.83%
94.1th percentile
The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2.21, when the DNS backend in the Name Service Switch configuration is enabled, allows remote attackers to cause a denial of service (infinite loop) by sending a positive answer while a network name is being process.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | glibc | < glibc 2.19-14 (bookworm) | glibc 2.19-14 (bookworm) |
| eglibc | eglibc | >= 0 < 2.19-0ubuntu6.6 | 2.19-0ubuntu6.6 |
| gnu | glibc | <= 2.20 | — |
| gnu | glibc | >= 0 < 2.19-14 | 2.19-14 |
| gnu | glibc | >= 0 < 2.19-14 | 2.19-14 |
| gnu | glibc | >= 0 < 2.19-14 | 2.19-14 |
| gnu | glibc | >= 0 < 2.19-14 | 2.19-14 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9rf5-3j57-32x7: The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2
ghsa_unreviewed·2022-05-14
CVE-2014-9402 [HIGH] GHSA-9rf5-3j57-32x7: The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2
The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2.21, when the DNS backend in the Name Service Switch configuration is enabled, allows remote attackers to cause a denial of service (infinite loop) by sending a positive answer while a network name is being process.
OSV
eglibc, glibc vulnerabilities
osv·2015-02-26·CVSS 5.0
CVE-2013-7423 [MEDIUM] eglibc, glibc vulnerabilities
eglibc, glibc vulnerabilities
Arnaud Le Blanc discovered that the GNU C Library incorrectly handled file
descriptors when resolving DNS queries under high load. This may cause a
denial of service in other applications, or an information leak. This issue
only affected Ubuntu 10.04 LTS, Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.
(CVE-2013-7423)
It was discovered that the GNU C Library incorrectly handled receiving a
positive answer while processing the network name when performing DNS
resolution. A remote attacker could use this issue to cause the GNU C
Library to hang, resulting in a denial of service. (CVE-2014-9402)
Joseph Myers discovered that the GNU C Library wscanf function incorrectly
handled memory. A remote attacker could possibly use this issue to cause
the GNU C Library to crash,
OSV
CVE-2014-9402: The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2
osv·2015-02-24·CVSS 7.8
CVE-2014-9402 [HIGH] CVE-2014-9402: The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2
The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2.21, when the DNS backend in the Name Service Switch configuration is enabled, allows remote attackers to cause a denial of service (infinite loop) by sending a positive answer while a network name is being process.
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2015-02-26·CVSS 5.0
CVE-2013-7423 [MEDIUM] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in the GNU C Library.
Arnaud Le Blanc discovered that the GNU C Library incorrectly handled file
descriptors when resolving DNS queries under high load. This may cause a
denial of service in other applications, or an information leak. This issue
only affected Ubuntu 10.04 LTS, Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.
(CVE-2013-7423)
It was discovered that the GNU C Library incorrectly handled receiving a
positive answer while processing the network name when performing DNS
resolution. A remote attacker could use this issue to cause the GNU C
Library to hang, resulting in a denial of service. (CVE-2014-9402)
Joseph Myers discovered that the GNU C Library wscanf function incorrectly
handled memory. A remote at
Red Hat
glibc: denial of service in getnetbyname function
vendor_redhat·2014-11-20·CVSS 7.8
CVE-2014-9402 [HIGH] CWE-835 glibc: denial of service in getnetbyname function
glibc: denial of service in getnetbyname function
The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2.21, when the DNS backend in the Name Service Switch configuration is enabled, allows remote attackers to cause a denial of service (infinite loop) by sending a positive answer while a network name is being process.
Statement: A non-standard system configuration ("networks: file dns" in /etc/nsswitch.conf) and possibly a DNS spoofing attack is required to exploit this flaw.
Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: g
Debian
CVE-2014-9402: glibc - The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2...
vendor_debian·2014·CVSS 7.8
CVE-2014-9402 [HIGH] CVE-2014-9402: glibc - The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2...
The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2.21, when the DNS backend in the Name Service Switch configuration is enabled, allows remote attackers to cause a denial of service (infinite loop) by sending a positive answer while a network name is being process.
Scope: local
bookworm: resolved (fixed in 2.19-14)
bullseye: resolved (fixed in 2.19-14)
forky: resolved (fixed in 2.19-14)
sid: resolved (fixed in 2.19-14)
trixie: resolved (fixed in 2.19-14)
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-updates/2015-02/msg00089.htmlhttp://packetstormsecurity.com/files/153278/WAGO-852-Industrial-Managed-Switch-Series-Code-Execution-Hardcoded-Credentials.htmlhttp://packetstormsecurity.com/files/154361/Cisco-Device-Hardcoded-Credentials-GNU-glibc-BusyBox.htmlhttp://seclists.org/fulldisclosure/2019/Jun/18http://seclists.org/fulldisclosure/2019/Sep/7http://www.openwall.com/lists/oss-security/2014/12/18/1http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.securityfocus.com/bid/71670http://www.ubuntu.com/usn/USN-2519-1https://access.redhat.com/errata/RHSA-2018:0805https://seclists.org/bugtraq/2019/Jun/14https://seclists.org/bugtraq/2019/Sep/7https://security.gentoo.org/glsa/201602-02https://sourceware.org/bugzilla/show_bug.cgi?id=17630http://lists.opensuse.org/opensuse-updates/2015-02/msg00089.htmlhttp://packetstormsecurity.com/files/153278/WAGO-852-Industrial-Managed-Switch-Series-Code-Execution-Hardcoded-Credentials.htmlhttp://packetstormsecurity.com/files/154361/Cisco-Device-Hardcoded-Credentials-GNU-glibc-BusyBox.htmlhttp://seclists.org/fulldisclosure/2019/Jun/18http://seclists.org/fulldisclosure/2019/Sep/7http://www.openwall.com/lists/oss-security/2014/12/18/1http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.securityfocus.com/bid/71670http://www.ubuntu.com/usn/USN-2519-1https://access.redhat.com/errata/RHSA-2018:0805https://seclists.org/bugtraq/2019/Jun/14https://seclists.org/bugtraq/2019/Sep/7https://security.gentoo.org/glsa/201602-02https://sourceware.org/bugzilla/show_bug.cgi?id=17630
2015-02-24
Published