CVE-2016-5417
published 2017-02-17CVE-2016-5417: Memory leak in the __res_vinit function in the IPv6 name server management code in libresolv in GNU C Library (aka glibc or libc6) before 2.24 allows remote…
PriorityP335high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
3.36%
87.5th percentile
Memory leak in the __res_vinit function in the IPv6 name server management code in libresolv in GNU C Library (aka glibc or libc6) before 2.24 allows remote attackers to cause a denial of service (memory consumption) by leveraging partial initialization of internal resolver data structures.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.22-4 (bookworm) | glibc 2.22-4 (bookworm) |
| eglibc | eglibc | >= 0 < 2.19-0ubuntu6.10 | 2.19-0ubuntu6.10 |
| eglibc | eglibc | >= 0 < 2.19-0ubuntu6.11 | 2.19-0ubuntu6.11 |
| gnu | glibc | <= 2.23 | — |
| gnu | glibc | >= 0 < 2.22-4 | 2.22-4 |
| gnu | glibc | >= 0 < 2.22-4 | 2.22-4 |
| gnu | glibc | >= 0 < 2.22-4 | 2.22-4 |
| gnu | glibc | >= 0 < 2.22-4 | 2.22-4 |
| gnu | glibc | >= 0 < 2.23-0ubuntu6 | 2.23-0ubuntu6 |
| gnu | glibc | >= 0 < 2.23-0ubuntu7 | 2.23-0ubuntu7 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_ubuntu8.1HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNU C Library regression
vendor_ubuntu·2017-03-24·CVSS 8.1
CVE-2016-3706 [HIGH] GNU C Library regression
Title: GNU C Library regression
Summary: USN-3239-1 introduced a regression in the GNU C Library.
USN-3239-1 fixed vulnerabilities in the GNU C Library. Unfortunately,
the fix for CVE-2016-3706 introduced a regression that in some
circumstances prevented IPv6 addresses from resolving. This update
reverts the change in Ubuntu 12.04 LTS. We apologize for the error.
Original advisory details:
It was discovered that the GNU C Library incorrectly handled the
strxfrm() function. An attacker could use this issue to cause a denial
of service or possibly execute arbitrary code. This issue only affected
Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2015-8982)
It was discovered that an integer overflow existed in the
_IO_wstr_overflow() function of the GNU C Library. An attacker could
use this to
Ubuntu
GNU C Library Regression
vendor_ubuntu·2017-03-21·CVSS 7.5
CVE-2015-5180 [HIGH] GNU C Library Regression
Title: GNU C Library Regression
Summary: USN-3239-1 introduced a regression in the GNU C Library.
USN-3239-1 fixed vulnerabilities in the GNU C Library. Unfortunately,
the fix for CVE-2015-5180 introduced an internal ABI change within
the resolver library. This update reverts the change. We apologize
for the inconvenience.
Please note that long-running services that were restarted to compensate
for the USN-3239-1 update may need to be restarted again.
Original advisory details:
It was discovered that the GNU C Library incorrectly handled the
strxfrm() function. An attacker could use this issue to cause a denial
of service or possibly execute arbitrary code. This issue only affected
Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2015-8982)
It was discovered that an integer overflow exist
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2017-03-21·CVSS 7.5
CVE-2015-5180 [HIGH] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in the GNU C Library.
It was discovered that the GNU C Library incorrectly handled the
strxfrm() function. An attacker could use this issue to cause a denial
of service or possibly execute arbitrary code. This issue only affected
Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2015-8982)
It was discovered that an integer overflow existed in the
_IO_wstr_overflow() function of the GNU C Library. An attacker could
use this to cause a denial of service or possibly execute arbitrary
code. This issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04
LTS. (CVE-2015-8983)
It was discovered that the fnmatch() function in the GNU C Library
did not properly handle certain malformed patterns. An attacker could
use this to
Red Hat
glibc: per-thread memory leak in __res_vinit with IPv6 nameservers
vendor_redhat·2016-08-02·CVSS 7.5
CVE-2016-5417 [HIGH] glibc: per-thread memory leak in __res_vinit with IPv6 nameservers
glibc: per-thread memory leak in __res_vinit with IPv6 nameservers
Memory leak in the __res_vinit function in the IPv6 name server management code in libresolv in GNU C Library (aka glibc or libc6) before 2.24 allows remote attackers to cause a denial of service (memory consumption) by leveraging partial initialization of internal resolver data structures.
Package: compat-glibc (Red Hat Enterprise Linux 5) - Not affected
Package: glibc (Red Hat Enterprise Linux 5) - Not affected
Package: compat-glibc (Red Hat Enterprise Linux 6) - Not affected
Package: glibc (Red Hat Enterprise Linux 6) - Not affected
Package: compat-glibc (Red Hat Enterprise Linux 7) - Not affected
Package: glibc (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2016-5417: glibc - Memory leak in the __res_vinit function in the IPv6 name server management code ...
vendor_debian·2016·CVSS 7.5
CVE-2016-5417 [HIGH] CVE-2016-5417: glibc - Memory leak in the __res_vinit function in the IPv6 name server management code ...
Memory leak in the __res_vinit function in the IPv6 name server management code in libresolv in GNU C Library (aka glibc or libc6) before 2.24 allows remote attackers to cause a denial of service (memory consumption) by leveraging partial initialization of internal resolver data structures.
Scope: local
bookworm: resolved (fixed in 2.22-4)
bullseye: resolved (fixed in 2.22-4)
forky: resolved (fixed in 2.22-4)
sid: resolved (fixed in 2.22-4)
trixie: resolved (fixed in 2.22-4)
GHSA
GHSA-qqpx-rhfx-8mgf: Memory leak in the __res_vinit function in the IPv6 name server management code in libresolv in GNU C Library (aka glibc or libc6) before 2
ghsa_unreviewed·2022-05-17
CVE-2016-5417 [HIGH] GHSA-qqpx-rhfx-8mgf: Memory leak in the __res_vinit function in the IPv6 name server management code in libresolv in GNU C Library (aka glibc or libc6) before 2
Memory leak in the __res_vinit function in the IPv6 name server management code in libresolv in GNU C Library (aka glibc or libc6) before 2.24 allows remote attackers to cause a denial of service (memory consumption) by leveraging partial initialization of internal resolver data structures.
OSV
eglibc, glibc vulnerabilities
osv·2017-03-21·CVSS 7.5
CVE-2015-8982 [HIGH] eglibc, glibc vulnerabilities
eglibc, glibc vulnerabilities
It was discovered that the GNU C Library incorrectly handled the
strxfrm() function. An attacker could use this issue to cause a denial
of service or possibly execute arbitrary code. This issue only affected
Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2015-8982)
It was discovered that an integer overflow existed in the
_IO_wstr_overflow() function of the GNU C Library. An attacker could
use this to cause a denial of service or possibly execute arbitrary
code. This issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04
LTS. (CVE-2015-8983)
It was discovered that the fnmatch() function in the GNU C Library
did not properly handle certain malformed patterns. An attacker could
use this to cause a denial of service. This issue only affected Ubuntu
12.04 LTS and U
OSV
eglibc, glibc regression
osv·2017-03-21·CVSS 7.5
CVE-2015-5180 [HIGH] eglibc, glibc regression
eglibc, glibc regression
USN-3239-1 fixed vulnerabilities in the GNU C Library. Unfortunately,
the fix for CVE-2015-5180 introduced an internal ABI change within
the resolver library. This update reverts the change. We apologize
for the inconvenience.
Please note that long-running services that were restarted to compensate
for the USN-3239-1 update may need to be restarted again.
Original advisory details:
It was discovered that the GNU C Library incorrectly handled the
strxfrm() function. An attacker could use this issue to cause a denial
of service or possibly execute arbitrary code. This issue only affected
Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2015-8982)
It was discovered that an integer overflow existed in the
_IO_wstr_overflow() function of the GNU C Library. An attacker c
OSV
CVE-2016-5417: Memory leak in the __res_vinit function in the IPv6 name server management code in libresolv in GNU C Library (aka glibc or libc6) before 2
osv·2017-02-17·CVSS 7.5
CVE-2016-5417 [HIGH] CVE-2016-5417: Memory leak in the __res_vinit function in the IPv6 name server management code in libresolv in GNU C Library (aka glibc or libc6) before 2
Memory leak in the __res_vinit function in the IPv6 name server management code in libresolv in GNU C Library (aka glibc or libc6) before 2.24 allows remote attackers to cause a denial of service (memory consumption) by leveraging partial initialization of internal resolver data structures.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2016/08/02/5http://www.securityfocus.com/bid/92257https://sourceware.org/bugzilla/show_bug.cgi?id=19257https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commitdiff%3Bh=2212c1420c92a33b0e0bd9a34938c9814a56c0f7https://www.sourceware.org/ml/libc-alpha/2016-08/msg00212.htmlhttp://www.openwall.com/lists/oss-security/2016/08/02/5http://www.securityfocus.com/bid/92257https://sourceware.org/bugzilla/show_bug.cgi?id=19257https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commitdiff%3Bh=2212c1420c92a33b0e0bd9a34938c9814a56c0f7https://www.sourceware.org/ml/libc-alpha/2016-08/msg00212.html
2017-02-17
Published