CVE-2017-12132
published 2017-08-01CVE-2017-12132: The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2.26, when EDNS support is enabled, will solicit large UDP responses from name…
PriorityP427medium5.9CVSS 3.0
AVNACHPRNUINSUCNIHAN
EPSS
1.88%
77.3th percentile
The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2.26, when EDNS support is enabled, will solicit large UDP responses from name servers, potentially simplifying off-path DNS spoofing attacks due to IP fragmentation.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.25-1 (bookworm) | glibc 2.25-1 (bookworm) |
| gnu | glibc | <= 2.25 | — |
| gnu | glibc | >= 0 < 2.25-1 | 2.25-1 |
| gnu | glibc | >= 0 < 2.25-1 | 2.25-1 |
| gnu | glibc | >= 0 < 2.25-1 | 2.25-1 |
| gnu | glibc | >= 0 < 2.25-1 | 2.25-1 |
| gnu | glibc | >= 0 < 2.23-0ubuntu11.3+esm3 | 2.23-0ubuntu11.3+esm3 |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
glibc vulnerabilities
osv·2022-12-08·CVSS 5.9
CVE-2016-10228 [MEDIUM] glibc vulnerabilities
glibc vulnerabilities
Jan Engelhardt, Tavis Ormandy, and others discovered that the GNU C Library
iconv feature incorrectly handled certain input sequences. An attacker
could possibly use this issue to cause the GNU C Library to hang or crash,
resulting in a denial of service. (CVE-2016-10228, CVE-2019-25013,
CVE-2020-27618)
It was discovered that the GNU C Library did not properly handled DNS
responses when ENDS0 is enabled. An attacker could possibly use this issue
to cause fragmentation-based attacks. (CVE-2017-12132)
GHSA
GHSA-wjh5-4fq2-439w: The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2
ghsa_unreviewed·2022-05-13
CVE-2017-12132 [MEDIUM] CWE-770 GHSA-wjh5-4fq2-439w: The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2
The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2.26, when EDNS support is enabled, will solicit large UDP responses from name servers, potentially simplifying off-path DNS spoofing attacks due to IP fragmentation.
OSV
CVE-2017-12132: The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2
osv·2017-08-01·CVSS 5.9
CVE-2017-12132 [MEDIUM] CVE-2017-12132: The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2
The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2.26, when EDNS support is enabled, will solicit large UDP responses from name servers, potentially simplifying off-path DNS spoofing attacks due to IP fragmentation.
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2022-12-08·CVSS 5.9
CVE-2019-25013 [MEDIUM] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in GNU C Library.
Jan Engelhardt, Tavis Ormandy, and others discovered that the GNU C Library
iconv feature incorrectly handled certain input sequences. An attacker
could possibly use this issue to cause the GNU C Library to hang or crash,
resulting in a denial of service. (CVE-2016-10228, CVE-2019-25013,
CVE-2020-27618)
It was discovered that the GNU C Library did not properly handled DNS
responses when ENDS0 is enabled. An attacker could possibly use this issue
to cause fragmentation-based attacks. (CVE-2017-12132)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
glibc: Fragmentation attacks possible when EDNS0 is enabled
vendor_redhat·2017-04-07·CVSS 5.9
CVE-2017-12132 [MEDIUM] glibc: Fragmentation attacks possible when EDNS0 is enabled
glibc: Fragmentation attacks possible when EDNS0 is enabled
The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2.26, when EDNS support is enabled, will solicit large UDP responses from name servers, potentially simplifying off-path DNS spoofing attacks due to IP fragmentation.
Statement: This issue only affects systems which use a remote recursive resolver and enable EDNS0, either with the “edns0” option in /etc/resolv.conf, or using the RES_USE_EDNS0 or RES_USE_DNSSEC resolver flags. The underlying issue affects recursive resolvers such as BIND and Unbound as well, and has to be fixed separately there.
Package: compat-glibc (Red Hat Enterprise Linux 5) - Will not fix
Package: glibc (Red Hat Enterprise Linux 5) - Will not fix
Package: compat-glibc (Red Hat
Debian
CVE-2017-12132: glibc - The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2...
vendor_debian·2017·CVSS 5.9
CVE-2017-12132 [MEDIUM] CVE-2017-12132: glibc - The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2...
The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2.26, when EDNS support is enabled, will solicit large UDP responses from name servers, potentially simplifying off-path DNS spoofing attacks due to IP fragmentation.
Scope: local
bookworm: resolved (fixed in 2.25-1)
bullseye: resolved (fixed in 2.25-1)
forky: resolved (fixed in 2.25-1)
sid: resolved (fixed in 2.25-1)
trixie: resolved (fixed in 2.25-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-12132 glibc: Fragmentation attacks possible when ENDS0 is enabled [fedora-all]
bugzilla·2017-08-02·CVSS 5.9
CVE-2017-12132 [MEDIUM] CVE-2017-12132 glibc: Fragmentation attacks possible when ENDS0 is enabled [fedora-all]
CVE-2017-12132 glibc: Fragmentation attacks possible when ENDS0 is enabled [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supporte
Bugzilla
CVE-2017-12132 glibc: Fragmentation attacks possible when EDNS0 is enabled
bugzilla·2017-08-02·CVSS 5.9
CVE-2017-12132 [MEDIUM] CVE-2017-12132 glibc: Fragmentation attacks possible when EDNS0 is enabled
CVE-2017-12132 glibc: Fragmentation attacks possible when EDNS0 is enabled
The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2.26, when EDNS support is enabled, will solicit large UDP responses from name servers, potentially simplifying off-path DNS spoofing attacks due to IP fragmentation.
Upstream bug:
https://sourceware.org/bugzilla/show_bug.cgi?id=21361
Discussion:
Created glibc tracking bugs for this issue:
Affects: fedora-all [bug 1477530]
---
Statement:
This issue only affects systems which use a remote recursive resolver and enable EDNS0, either with the “edns0” option in /etc/resolv.conf, or using the RES_USE_EDNS0 or RES_USE_DNSSEC resolver flags. The underlying issue affects recursive resolvers such as BIND and Unbound as well, and has to be
http://www.securityfocus.com/bid/100598https://access.redhat.com/errata/RHSA-2018:0805https://arxiv.org/pdf/1205.4011.pdfhttps://sourceware.org/bugzilla/show_bug.cgi?id=21361http://www.securityfocus.com/bid/100598https://access.redhat.com/errata/RHSA-2018:0805https://arxiv.org/pdf/1205.4011.pdfhttps://sourceware.org/bugzilla/show_bug.cgi?id=21361
2017-08-01
Published