CVE-2018-19591
published 2018-12-04CVE-2018-19591: In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
5.53%
92.0th percentile
In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to the if_nametoindex() function.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.28-1 (bookworm) | glibc 2.28-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnu | glibc | <= 2.28 | — |
| gnu | glibc | >= 0 < 2.28-1 | 2.28-1 |
| gnu | glibc | >= 0 < 2.28-1 | 2.28-1 |
| gnu | glibc | >= 0 < 2.28-1 | 2.28-1 |
| gnu | glibc | >= 0 < 2.28-1 | 2.28-1 |
| gnu | glibc | >= 0 < 2.23-0ubuntu11.2 | 2.23-0ubuntu11.2 |
| gnu | glibc | >= 0 < 2.27-3ubuntu1.2 | 2.27-3ubuntu1.2 |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_glibc_2.28-12_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2020-07-06·CVSS 5.9
CVE-2017-12133 [MEDIUM] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in GNU C Library.
Florian Weimer discovered that the GNU C Library incorrectly handled
certain memory operations. A remote attacker could use this issue to cause
the GNU C Library to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2017-12133)
It was discovered that the GNU C Library incorrectly handled certain
SSE2-optimized memmove operations. A remote attacker could use this issue
to cause the GNU C Library to crash, resulting in a denial of service, or
possibly execute arbitrary code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2017-18269)
It was discovered that the GNU C Library incorrectly handled certain
pathname operati
Microsoft
In the GNU C Library (aka glibc or libc6) through 2.28 attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to
vendor_msrc·2018-12-11·CVSS 7.5
CVE-2018-19591 [HIGH] CWE-20 In the GNU C Library (aka glibc or libc6) through 2.28 attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to
In the GNU C Library (aka glibc or libc6) through 2.28 attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to the if_nametoindex() function.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is
Red Hat
glibc: file descriptor leak in if_nametoindex() in sysdeps/unix/sysv/linux/if_index.c
vendor_redhat·2018-11-27·CVSS 7.5
CVE-2018-19591 [HIGH] CWE-400 glibc: file descriptor leak in if_nametoindex() in sysdeps/unix/sysv/linux/if_index.c
glibc: file descriptor leak in if_nametoindex() in sysdeps/unix/sysv/linux/if_index.c
In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to the if_nametoindex() function.
Statement: This issue did not affect the versions of glibc as shipped with Red Hat Enterprise Linux 5, 6, and 7.
Package: compat-glibc (Red Hat Enterprise Linux 5) - Not affected
Package: glibc (Red Hat Enterprise Linux 5) - Not affected
Package: compat-glibc (Red Hat Enterprise Linux 6) - Not affected
Package: glibc (Red Hat Enterprise Linux 6) - Not affected
Package: compat-glibc (Red Hat Enterprise Linux 7) - Not affected
Package: glibc (Red Hat Enterprise Linux 7) -
Debian
CVE-2018-19591: glibc - In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a ...
vendor_debian·2018·CVSS 7.5
CVE-2018-19591 [HIGH] CVE-2018-19591: glibc - In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a ...
In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to the if_nametoindex() function.
Scope: local
bookworm: resolved (fixed in 2.28-1)
bullseye: resolved (fixed in 2.28-1)
forky: resolved (fixed in 2.28-1)
sid: resolved (fixed in 2.28-1)
trixie: resolved (fixed in 2.28-1)
GHSA
GHSA-x2fw-rj3g-6m95: In the GNU C Library (aka glibc or libc6) through 2
ghsa_unreviewed·2022-05-13
CVE-2018-19591 [HIGH] CWE-20 GHSA-x2fw-rj3g-6m95: In the GNU C Library (aka glibc or libc6) through 2
In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to the if_nametoindex() function.
OSV
glibc vulnerabilities
osv·2020-07-06·CVSS 5.9
CVE-2017-12133 [MEDIUM] glibc vulnerabilities
glibc vulnerabilities
Florian Weimer discovered that the GNU C Library incorrectly handled
certain memory operations. A remote attacker could use this issue to cause
the GNU C Library to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2017-12133)
It was discovered that the GNU C Library incorrectly handled certain
SSE2-optimized memmove operations. A remote attacker could use this issue
to cause the GNU C Library to crash, resulting in a denial of service, or
possibly execute arbitrary code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2017-18269)
It was discovered that the GNU C Library incorrectly handled certain
pathname operations. A remote attacker could use this issue to cause the
GNU C Library to cras
OSV
CVE-2018-19591: In the GNU C Library (aka glibc or libc6) through 2
osv·2018-12-04·CVSS 7.5
CVE-2018-19591 [HIGH] CVE-2018-19591: In the GNU C Library (aka glibc or libc6) through 2
In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to the if_nametoindex() function.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-19591 glibc: file descriptor leak in if_nametoindex() in sysdeps/unix/sysv/linux/if_index.c [fedora-all]
bugzilla·2018-11-27·CVSS 7.5
CVE-2018-19591 [HIGH] CVE-2018-19591 glibc: file descriptor leak in if_nametoindex() in sysdeps/unix/sysv/linux/if_index.c [fedora-all]
CVE-2018-19591 glibc: file descriptor leak in if_nametoindex() in sysdeps/unix/sysv/linux/if_index.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2018-19591 glibc: file descriptor leak in if_nametoindex() in sysdeps/unix/sysv/linux/if_index.c
bugzilla·2018-11-27·CVSS 7.5
CVE-2018-19591 [HIGH] CVE-2018-19591 glibc: file descriptor leak in if_nametoindex() in sysdeps/unix/sysv/linux/if_index.c
CVE-2018-19591 glibc: file descriptor leak in if_nametoindex() in sysdeps/unix/sysv/linux/if_index.c
A flaw was found in glibc before version 2.29. A file descriptor leak in if_nametoindex can lead to a denial of service due to resource exhaustion when processing getaddrinfo calls with crafted host names.
References:
https://sourceware.org/bugzilla/show_bug.cgi?id=23927
Upstream Patch:
https://sourceware.org/ml/libc-alpha/2018-11/msg00698.html
Discussion:
Created glibc tracking bugs for this issue:
Affects: fedora-all [bug 1654000]
---
Statement:
This issue did not affect the versions of glibc as shipped with Red Hat Enterprise Linux 5, 6, and 7.
---
glibc-2.27-35.fc28 has been pushed to the Fedora 28 stable repository. If problems still persist, please make note of it in this
http://www.securityfocus.com/bid/106037http://www.securitytracker.com/id/1042174https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BO7WHN52GFMC5F2I2232GFIPSSXWFV7G/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M52KE4YR3GNMHQUOS3DKAGZD5TQ5D5UH/https://security.gentoo.org/glsa/201903-09https://security.gentoo.org/glsa/201908-06https://security.netapp.com/advisory/ntap-20190321-0003/https://sourceware.org/bugzilla/show_bug.cgi?id=23927https://sourceware.org/git/?p=glibc.git%3Ba=blob_plain%3Bf=NEWS%3Bhb=HEADhttps://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commitdiff%3Bh=d527c860f5a3f0ed687bd03f0cb464612dc23408https://usn.ubuntu.com/4416-1/http://www.securityfocus.com/bid/106037http://www.securitytracker.com/id/1042174https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BO7WHN52GFMC5F2I2232GFIPSSXWFV7G/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M52KE4YR3GNMHQUOS3DKAGZD5TQ5D5UH/https://security.gentoo.org/glsa/201903-09https://security.gentoo.org/glsa/201908-06https://security.netapp.com/advisory/ntap-20190321-0003/https://sourceware.org/bugzilla/show_bug.cgi?id=23927https://sourceware.org/git/?p=glibc.git%3Ba=blob_plain%3Bf=NEWS%3Bhb=HEADhttps://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commitdiff%3Bh=d527c860f5a3f0ed687bd03f0cb464612dc23408https://usn.ubuntu.com/4416-1/
2018-12-04
Published