cbcvebase.
CVE-2018-19591
published 2018-12-04

CVE-2018-19591: In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to the if_nametoindex() function.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianglibc< glibc 2.28-1 (bookworm)glibc 2.28-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
gnuglibc<= 2.28
gnuglibc>= 0 < 2.28-12.28-1
gnuglibc>= 0 < 2.28-12.28-1
gnuglibc>= 0 < 2.28-12.28-1
gnuglibc>= 0 < 2.28-12.28-1
gnuglibc>= 0 < 2.23-0ubuntu11.22.23-0ubuntu11.2
gnuglibc>= 0 < 2.27-3ubuntu1.22.27-3ubuntu1.2
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_glibc_2.28-12_on_cbl_mariner_1.0

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH