CVE-2023-4527
published 2023-09-18CVE-2023-4527: A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via…
PriorityP335medium6.5CVSS 3.1
AVNACHPRNUINSUCLINAH
EPSS
1.51%
71.5th percentile
A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash.
Affected
39 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.36-9+deb12u3 (bookworm) | glibc 2.36-9+deb12u3 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnu | glibc | >= 0 < 2.36-9+deb12u3 | 2.36-9+deb12u3 |
| gnu | glibc | >= 0 < 2.37-9 | 2.37-9 |
| gnu | glibc | >= 0 < 2.37-9 | 2.37-9 |
| gnu | glibc | >= 0 < 2.35-0ubuntu3.4 | 2.35-0ubuntu3.4 |
| gnu | glibc | >= 2.36 < 2.36.113 | 2.36.113 |
| gnu | glibc | >= 2.37 < 2.37.38 | 2.37.38 |
| gnu | glibc | >= 2.38 < 2.38.19 | 2.38.19 |
| msrc | azl3_glibc_2.38-11_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| paloalto | pan-os | — | — |
| redhat | codeready_linux_builder_eus | — | — |
| redhat | codeready_linux_builder_eus_for_power_little_endian | — | — |
| redhat | codeready_linux_builder_eus_for_power_little_endian_eus | — | — |
| redhat | codeready_linux_builder_for_arm64 | — | — |
| redhat | codeready_linux_builder_for_arm64_eus | — | — |
| redhat | codeready_linux_builder_for_ibm_z_systems | — | — |
| redhat | codeready_linux_builder_for_ibm_z_systems_eus | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU Family
cisa_ics·2025-06-12
Siemens SIMATIC S7-1500 CPU Family
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU Family
Release DateJune 12, 2025
Alert CodeICSA-25-162-05
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.7
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU family
- Vulnerabilities: Missing Encryption of Sensitive Data, Out-of-bounds Read, Use After Free, Stack-
Palo Alto
PAN-SA-2024-0012 Informational Bulletin: OSS CVEs fixed in PAN-OS
vendor_paloalto·2024-10-29·CVSS 9.8
CVE-2019-17006 [CRITICAL] PAN-SA-2024-0012 Informational Bulletin: OSS CVEs fixed in PAN-OS
PAN-SA-2024-0012 Informational Bulletin: OSS CVEs fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2019-17006 This CVE is fixed in PAN-OS 10.2.0, and all later versions of PAN-OS. CVE-2021-3518 This CVE is fixed in PAN-OS 10.2.0, and all later versions of PAN-OS. CVE-2021-25219 This CVE is fixed in PAN-OS 10.2.3, and all later versions of PAN-OS. CVE-2021-27645 This CVE is fixed in PAN-OS 10.2.8, PAN-OS 11.0.2, and all later versions of PAN-OS. CVE-2021-34798 This CVE is fixed in PAN-OS 10.2.8, PAN-OS 11.0.2, and all later versions o
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2023-10-03·CVSS 6.5
CVE-2023-4911 [MEDIUM] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in GNU C Library.
It was discovered that the GNU C Library incorrectly handled the
GLIBC_TUNABLES environment variable. An attacker could possibly use this
issue to perform a privilege escalation attack. (CVE-2023-4911)
It was discovered that the GNU C Library incorrectly handled certain DNS
responses when the system was configured in no-aaaa mode. A remote attacker
could possibly use this issue to cause the GNU C Library to crash,
resulting in a denial of service. This issue only affected Ubuntu 23.04.
(CVE-2023-4527)
Instructions: After a standard system update you need to reboot your computer to make all
the necessary changes.
Microsoft
Glibc: stack read overflow in getaddrinfo in no-aaaa mode
vendor_msrc·2023-09-12·CVSS 6.5
CVE-2023-4527 [MEDIUM] CWE-121 Glibc: stack read overflow in getaddrinfo in no-aaaa mode
Glibc: stack read overflow in getaddrinfo in no-aaaa mode
NIST NVD Details: https://nvd.nist.gov/vuln/detail/CVE-2023-4527
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Requ
Red Hat
glibc: Stack read overflow in getaddrinfo in no-aaaa mode
vendor_redhat·2023-09-12·CVSS 6.5
CVE-2023-4527 [MEDIUM] CWE-121 glibc: Stack read overflow in getaddrinfo in no-aaaa mode
glibc: Stack read overflow in getaddrinfo in no-aaaa mode
A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash.
A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash.
Statement: This issue only affects systems configured with no-aaaa mode via /etc/resolv.conf.
Debian
CVE-2023-4527: glibc - A flaw was found in glibc. When the getaddrinfo function is called with the AF_U...
vendor_debian·2023·CVSS 6.5
CVE-2023-4527 [MEDIUM] CVE-2023-4527: glibc - A flaw was found in glibc. When the getaddrinfo function is called with the AF_U...
A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash.
Scope: local
bookworm: resolved (fixed in 2.36-9+deb12u3)
bullseye: resolved
forky: resolved (fixed in 2.37-9)
sid: resolved (fixed in 2.37-9)
trixie: resolved (fixed in 2.37-9)
OSV
glibc vulnerabilities
osv·2023-10-03·CVSS 6.5
CVE-2023-4911 [MEDIUM] glibc vulnerabilities
glibc vulnerabilities
It was discovered that the GNU C Library incorrectly handled the
GLIBC_TUNABLES environment variable. An attacker could possibly use this
issue to perform a privilege escalation attack. (CVE-2023-4911)
It was discovered that the GNU C Library incorrectly handled certain DNS
responses when the system was configured in no-aaaa mode. A remote attacker
could possibly use this issue to cause the GNU C Library to crash,
resulting in a denial of service. This issue only affected Ubuntu 23.04.
(CVE-2023-4527)
OSV
CVE-2023-4527: A flaw was found in glibc
osv·2023-09-18·CVSS 6.5
CVE-2023-4527 [MEDIUM] CVE-2023-4527: A flaw was found in glibc
A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash.
GHSA
GHSA-hmf7-f8gf-8f4p: A flaw was found in glibc
ghsa_unreviewed·2023-09-18
CVE-2023-4527 [MEDIUM] CWE-121 GHSA-hmf7-f8gf-8f4p: A flaw was found in glibc
A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2023:5453https://access.redhat.com/errata/RHSA-2023:5455https://access.redhat.com/security/cve/CVE-2023-4527https://bugzilla.redhat.com/show_bug.cgi?id=2234712http://www.openwall.com/lists/oss-security/2023/09/25/1https://access.redhat.com/errata/RHSA-2023:5453https://access.redhat.com/errata/RHSA-2023:5455https://access.redhat.com/security/cve/CVE-2023-4527https://bugzilla.redhat.com/show_bug.cgi?id=2234712https://lists.fedoraproject.org/archives/list/[email protected]/message/4DBUQRRPB47TC3NJOUIBVWUGFHBJAFDL/https://lists.fedoraproject.org/archives/list/[email protected]/message/DFG4P76UHHZEWQ26FWBXG76N2QLKKPZA/https://lists.fedoraproject.org/archives/list/[email protected]/message/NDAQWHTSVOCOZ5K6KPIWKRT3JX4RTZUR/https://security.gentoo.org/glsa/202310-03https://security.netapp.com/advisory/ntap-20231116-0012/https://cert-portal.siemens.com/productcert/html/ssa-082556.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-831302.html
2023-09-18
Published