UBUNTU-CVE-2014-3484
Dashboard / Vulnerabilities / UBUNTU-CVE-2014-3484
UBUNTU-CVE-2014-3484
Summary:
Details: Multiple stack-based buffer overflows in the __dn_expand function in network/dn_expand.c in musl libc 1.1x before 1.1.2 and 0.9.13 through 1.0.3 allow remote attackers to (1) have unspecified impact via an invalid name length in a DNS response or (2) cause a denial of service (crash) via an invalid name length in a DNS response, related to an infinite loop with no output.
References: https://ubuntu.com/security/CVE-2014-3484, https://marc.info/?l=oss-security&m=140210606626487&w=2, https://www.cve.org/CVERecord?id=CVE-2014-3484, https://ubuntu.com/security/notices/USN-4768-1
Affected packages
Package
Name: musl
Purl: pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
