CVE-2016-3075
published 2016-06-01CVE-2016-3075: Stack-based buffer overflow in the nss_dns implementation of the getnetbyname function in GNU C Library (aka glibc) before 2.24 allows context-dependent…
PriorityP338high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
7.63%
93.9th percentile
Stack-based buffer overflow in the nss_dns implementation of the getnetbyname function in GNU C Library (aka glibc) before 2.24 allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a long name.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | glibc | < glibc 2.22-6 (bookworm) | glibc 2.22-6 (bookworm) |
| eglibc | eglibc | >= 0 < 2.19-0ubuntu6.8 | 2.19-0ubuntu6.8 |
| eglibc | eglibc | >= 0 < 2.19-0ubuntu6.9 | 2.19-0ubuntu6.9 |
| fedoraproject | fedora | — | — |
| gnu | glibc | <= 2.23 | — |
| gnu | glibc | >= 0 < 2.22-6 | 2.22-6 |
| gnu | glibc | >= 0 < 2.22-6 | 2.22-6 |
| gnu | glibc | >= 0 < 2.22-6 | 2.22-6 |
| gnu | glibc | >= 0 < 2.22-6 | 2.22-6 |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7x96-w64p-8chw: Stack-based buffer overflow in the nss_dns implementation of the getnetbyname function in GNU C Library (aka glibc) before 2
ghsa_unreviewed·2022-05-14
CVE-2016-3075 [HIGH] CWE-119 GHSA-7x96-w64p-8chw: Stack-based buffer overflow in the nss_dns implementation of the getnetbyname function in GNU C Library (aka glibc) before 2
Stack-based buffer overflow in the nss_dns implementation of the getnetbyname function in GNU C Library (aka glibc) before 2.24 allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a long name.
OSV
CVE-2016-3075: Stack-based buffer overflow in the nss_dns implementation of the getnetbyname function in GNU C Library (aka glibc) before 2
osv·2016-06-01·CVSS 7.5
CVE-2016-3075 [HIGH] CVE-2016-3075: Stack-based buffer overflow in the nss_dns implementation of the getnetbyname function in GNU C Library (aka glibc) before 2
Stack-based buffer overflow in the nss_dns implementation of the getnetbyname function in GNU C Library (aka glibc) before 2.24 allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a long name.
OSV
eglibc, glibc regression
osv·2016-05-26·CVSS 2.6
CVE-2014-9761 [LOW] eglibc, glibc regression
eglibc, glibc regression
USN-2985-1 fixed vulnerabilities in the GNU C Library. The fix for
CVE-2014-9761 introduced a regression which affected applications that
use the libm library but were not fully restarted after the upgrade.
This update removes the fix for CVE-2014-9761 and a future update
will be provided to address this issue.
We apologize for the inconvenience.
Original advisory details:
Martin Carpenter discovered that pt_chown in the GNU C Library did not
properly check permissions for tty files. A local attacker could use this
to gain administrative privileges or expose sensitive information.
(CVE-2013-2207, CVE-2016-2856)
Robin Hack discovered that the Name Service Switch (NSS) implementation in
the GNU C Library did not properly manage its file descriptors. An attacker
OSV
eglibc, glibc vulnerabilities
osv·2016-05-25·CVSS 2.6
CVE-2013-2207 [LOW] eglibc, glibc vulnerabilities
eglibc, glibc vulnerabilities
Martin Carpenter discovered that pt_chown in the GNU C Library did not
properly check permissions for tty files. A local attacker could use this
to gain administrative privileges or expose sensitive information.
(CVE-2013-2207, CVE-2016-2856)
Robin Hack discovered that the Name Service Switch (NSS) implementation in
the GNU C Library did not properly manage its file descriptors. An attacker
could use this to cause a denial of service (infinite loop).
(CVE-2014-8121)
Joseph Myers discovered that the GNU C Library did not properly handle long
arguments to functions returning a representation of Not a Number (NaN). An
attacker could use this to cause a denial of service (stack exhaustion
leading to an application crash) or possibly execute arbitrary code.
(CVE
Ubuntu
GNU C Library regression
vendor_ubuntu·2016-05-26·CVSS 2.6
CVE-2014-9761 [LOW] GNU C Library regression
Title: GNU C Library regression
Summary: USN-2985-1 introduced a regression in the GNU C Library.
USN-2985-1 fixed vulnerabilities in the GNU C Library. The fix for
CVE-2014-9761 introduced a regression which affected applications that
use the libm library but were not fully restarted after the upgrade.
This update removes the fix for CVE-2014-9761 and a future update
will be provided to address this issue.
We apologize for the inconvenience.
Original advisory details:
Martin Carpenter discovered that pt_chown in the GNU C Library did not
properly check permissions for tty files. A local attacker could use this
to gain administrative privileges or expose sensitive information.
(CVE-2013-2207, CVE-2016-2856)
Robin Hack discovered that the Name Service Switch (NSS) implementation in
th
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2016-05-25·CVSS 2.6
CVE-2013-2207 [LOW] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in the GNU C Library.
Martin Carpenter discovered that pt_chown in the GNU C Library did not
properly check permissions for tty files. A local attacker could use this
to gain administrative privileges or expose sensitive information.
(CVE-2013-2207, CVE-2016-2856)
Robin Hack discovered that the Name Service Switch (NSS) implementation in
the GNU C Library did not properly manage its file descriptors. An attacker
could use this to cause a denial of service (infinite loop).
(CVE-2014-8121)
Joseph Myers discovered that the GNU C Library did not properly handle long
arguments to functions returning a representation of Not a Number (NaN). An
attacker could use this to cause a denial of service (stack exhaustion
Red Hat
glibc: Stack overflow in nss_dns_getnetbyname_r
vendor_redhat·2016-03-29·CVSS 7.5
CVE-2016-3075 [HIGH] CWE-121 glibc: Stack overflow in nss_dns_getnetbyname_r
glibc: Stack overflow in nss_dns_getnetbyname_r
Stack-based buffer overflow in the nss_dns implementation of the getnetbyname function in GNU C Library (aka glibc) before 2.24 allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a long name.
A stack overflow vulnerability was found in _nss_dns_getnetbyname_r. On systems with nsswitch configured to include "networks: dns" with a privileged or network-facing service that would attempt to resolve user-provided network names, an attacker could provide an excessively long network name, resulting in stack corruption and code execution.
Package: compat-glibc (Red Hat Enterprise Linux 5) - Will not fix
Package: glibc (Red Hat Enterprise Linux 5) - Will not fix
Package: compat-glibc (Red
Debian
CVE-2016-3075: glibc - Stack-based buffer overflow in the nss_dns implementation of the getnetbyname fu...
vendor_debian·2016·CVSS 7.5
CVE-2016-3075 [HIGH] CVE-2016-3075: glibc - Stack-based buffer overflow in the nss_dns implementation of the getnetbyname fu...
Stack-based buffer overflow in the nss_dns implementation of the getnetbyname function in GNU C Library (aka glibc) before 2.24 allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a long name.
Scope: local
bookworm: resolved (fixed in 2.22-6)
bullseye: resolved (fixed in 2.22-6)
forky: resolved (fixed in 2.22-6)
sid: resolved (fixed in 2.22-6)
trixie: resolved (fixed in 2.22-6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-3075 glibc: Stack overflow in nss_dns_getnetbyname_r
bugzilla·2016-03-29·CVSS 7.5
CVE-2016-3075 [HIGH] CVE-2016-3075 glibc: Stack overflow in nss_dns_getnetbyname_r
CVE-2016-3075 glibc: Stack overflow in nss_dns_getnetbyname_r
A stack overflow vulnerability (unbounded allocation) in _nss_dns_getnetbyname_r function was found.
Discussion:
Acknowledgments:
Name: Florian Weimer (Red Hat)
---
Created attachment 1141161
Crash report
---
Upstream bug: https://sourceware.org/bugzilla/show_bug.cgi?id=19879
Proposed patch: https://sourceware.org/ml/libc-alpha/2016-03/msg00692.html
---
Created glibc tracking bugs for this issue:
Affects: fedora-all [bug 1321954]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:2573 https://rhn.redhat.com/errata/RHSA-2016-2573.html
Bugzilla
CVE-2016-3075 glibc: Stack overflow in nss_dns_getnetbyname_r [fedora-all]
bugzilla·2016-03-29·CVSS 7.5
CVE-2016-3075 [HIGH] CVE-2016-3075 glibc: Stack overflow in nss_dns_getnetbyname_r [fedora-all]
CVE-2016-3075 glibc: Stack overflow in nss_dns_getnetbyname_r [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fed
http://lists.fedoraproject.org/pipermail/package-announce/2016-May/184626.htmlhttp://lists.opensuse.org/opensuse-updates/2016-06/msg00030.htmlhttp://lists.opensuse.org/opensuse-updates/2016-07/msg00039.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2573.htmlhttp://www.securityfocus.com/bid/85732http://www.ubuntu.com/usn/USN-2985-1https://security.gentoo.org/glsa/201702-11https://sourceware.org/bugzilla/show_bug.cgi?id=19879https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=317b199b4aff8cfa27f2302ab404d2bb5032b9a4http://lists.fedoraproject.org/pipermail/package-announce/2016-May/184626.htmlhttp://lists.opensuse.org/opensuse-updates/2016-06/msg00030.htmlhttp://lists.opensuse.org/opensuse-updates/2016-07/msg00039.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2573.htmlhttp://www.securityfocus.com/bid/85732http://www.ubuntu.com/usn/USN-2985-1https://security.gentoo.org/glsa/201702-11https://sourceware.org/bugzilla/show_bug.cgi?id=19879https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=317b199b4aff8cfa27f2302ab404d2bb5032b9a4
2016-06-01
Published