CVE-2017-12133
published 2017-09-07CVE-2017-12133: Use-after-free vulnerability in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) before 2.26 allows remote attackers to…
PriorityP430medium5.9CVSS 3.0
AVNACHPRNUINSUCNIHAN
EPSS
2.40%
82.3th percentile
Use-after-free vulnerability in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) before 2.26 allows remote attackers to have unspecified impact via vectors related to error path.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.24-15 (bookworm) | glibc 2.24-15 (bookworm) |
| gnu | glibc | <= 2.25 | — |
| gnu | glibc | >= 0 < 2.24-15 | 2.24-15 |
| gnu | glibc | >= 0 < 2.24-15 | 2.24-15 |
| gnu | glibc | >= 0 < 2.24-15 | 2.24-15 |
| gnu | glibc | >= 0 < 2.24-15 | 2.24-15 |
| gnu | glibc | >= 0 < 2.23-0ubuntu11.2 | 2.23-0ubuntu11.2 |
| gnu | glibc | >= 0 < 2.27-3ubuntu1.2 | 2.27-3ubuntu1.2 |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v9xh-wvfv-7mhr: Use-after-free vulnerability in the clntudp_call function in sunrpc/clnt_udp
ghsa_unreviewed·2022-05-13
CVE-2017-12133 [MEDIUM] CWE-416 GHSA-v9xh-wvfv-7mhr: Use-after-free vulnerability in the clntudp_call function in sunrpc/clnt_udp
Use-after-free vulnerability in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) before 2.26 allows remote attackers to have unspecified impact via vectors related to error path.
OSV
glibc vulnerabilities
osv·2020-07-06·CVSS 5.9
CVE-2017-12133 [MEDIUM] glibc vulnerabilities
glibc vulnerabilities
Florian Weimer discovered that the GNU C Library incorrectly handled
certain memory operations. A remote attacker could use this issue to cause
the GNU C Library to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2017-12133)
It was discovered that the GNU C Library incorrectly handled certain
SSE2-optimized memmove operations. A remote attacker could use this issue
to cause the GNU C Library to crash, resulting in a denial of service, or
possibly execute arbitrary code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2017-18269)
It was discovered that the GNU C Library incorrectly handled certain
pathname operations. A remote attacker could use this issue to cause the
GNU C Library to cras
OSV
CVE-2017-12133: Use-after-free vulnerability in the clntudp_call function in sunrpc/clnt_udp
osv·2017-09-07·CVSS 5.9
CVE-2017-12133 [MEDIUM] CVE-2017-12133: Use-after-free vulnerability in the clntudp_call function in sunrpc/clnt_udp
Use-after-free vulnerability in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) before 2.26 allows remote attackers to have unspecified impact via vectors related to error path.
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2020-07-06·CVSS 5.9
CVE-2017-12133 [MEDIUM] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in GNU C Library.
Florian Weimer discovered that the GNU C Library incorrectly handled
certain memory operations. A remote attacker could use this issue to cause
the GNU C Library to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2017-12133)
It was discovered that the GNU C Library incorrectly handled certain
SSE2-optimized memmove operations. A remote attacker could use this issue
to cause the GNU C Library to crash, resulting in a denial of service, or
possibly execute arbitrary code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2017-18269)
It was discovered that the GNU C Library incorrectly handled certain
pathname operati
Red Hat
glibc: Use-after-free read access in clntudp_call in sunrpc
vendor_redhat·2017-02-08·CVSS 5.9
CVE-2017-12133 [MEDIUM] CWE-416 glibc: Use-after-free read access in clntudp_call in sunrpc
glibc: Use-after-free read access in clntudp_call in sunrpc
Use-after-free vulnerability in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) before 2.26 allows remote attackers to have unspecified impact via vectors related to error path.
Statement: This issue does not affect the versions of gcc compiler shipped with Red Hat Enterprise Linux, because The patch for CVE-2016-4429 was not backported for those versions of glibc.
Package: compat-glibc (Red Hat Enterprise Linux 5) - Not affected
Package: glibc (Red Hat Enterprise Linux 5) - Not affected
Package: compat-glibc (Red Hat Enterprise Linux 6) - Not affected
Package: glibc (Red Hat Enterprise Linux 6) - Not affected
Package: compat-glibc (Red Hat Enterprise Linux 7) - Not affected
Package
Debian
CVE-2017-12133: glibc - Use-after-free vulnerability in the clntudp_call function in sunrpc/clnt_udp.c i...
vendor_debian·2017·CVSS 5.9
CVE-2017-12133 [MEDIUM] CVE-2017-12133: glibc - Use-after-free vulnerability in the clntudp_call function in sunrpc/clnt_udp.c i...
Use-after-free vulnerability in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) before 2.26 allows remote attackers to have unspecified impact via vectors related to error path.
Scope: local
bookworm: resolved (fixed in 2.24-15)
bullseye: resolved (fixed in 2.24-15)
forky: resolved (fixed in 2.24-15)
sid: resolved (fixed in 2.24-15)
trixie: resolved (fixed in 2.24-15)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-12133 glibc: Use-after-free read access in clntudp_call in sunrpc
bugzilla·2017-08-04·CVSS 5.9
CVE-2017-12133 [MEDIUM] CVE-2017-12133 glibc: Use-after-free read access in clntudp_call in sunrpc
CVE-2017-12133 glibc: Use-after-free read access in clntudp_call in sunrpc
CVE-2016-4429 fix introduced a use-after-free vulnerability in clntudp_call of sunrpc.
Upstream bug:
https://sourceware.org/bugzilla/show_bug.cgi?id=21115
Upstream patch:
https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=d42eed4a044e5e10dfb885cf9891c2518a72a491
Discussion:
Created glibc tracking bugs for this issue:
Affects: fedora-all [bug 1478289]
---
Statement:
This issue does not affect the versions of gcc compiler shipped with Red Hat Enterprise Linux, because The patch for CVE-2016-4429 was not backported for those versions of glibc.
Bugzilla
CVE-2017-12133 glibc: Use-after-free read access in clntudp_call in sunrpc [fedora-all]
bugzilla·2017-08-04·CVSS 5.9
CVE-2017-12133 [MEDIUM] CVE-2017-12133 glibc: Use-after-free read access in clntudp_call in sunrpc [fedora-all]
CVE-2017-12133 glibc: Use-after-free read access in clntudp_call in sunrpc [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supporte
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SYZL6PAKI73XYRJYL5VLDGA4FFGWMB7A/https://sourceware.org/bugzilla/show_bug.cgi?id=21115https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=d42eed4a044e5e10dfb885cf9891c2518a72a491https://usn.ubuntu.com/4416-1/https://www.securityfocus.com/bid/100679https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SYZL6PAKI73XYRJYL5VLDGA4FFGWMB7A/https://sourceware.org/bugzilla/show_bug.cgi?id=21115https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=d42eed4a044e5e10dfb885cf9891c2518a72a491https://usn.ubuntu.com/4416-1/https://www.securityfocus.com/bid/100679
2017-09-07
Published