UBUNTU-CVE-2017-15650
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-15650
UBUNTU-CVE-2017-15650
Summary:
Details: musl libc before 1.1.17 has a buffer overflow via crafted DNS replies because dns_parse_callback in network/lookup_name.c does not restrict the number of addresses, and thus an attacker can provide an unexpected number by sending A records in a reply to an AAAA query.
References: https://ubuntu.com/security/CVE-2017-15650, https://git.musl-libc.org/cgit/musl/patch/?id=45ca5d3fcb6f874bf5ba55d0e9651cef68515395, http://git.musl-libc.org/cgit/musl/commit/?id=45ca5d3fcb6f874bf5ba55d0e9651cef68515395, http://git.musl-libc.org/cgit/musl/tree/WHATSNEW, http://openwall.com/lists/oss-security/2017/10/19/5, https://www.cve.org/CVERecord?id=CVE-2017-15650, https://ubuntu.com/security/notices/USN-4768-1
Affected packages
Package
Name: musl
Purl: pkg:deb/ubuntu/[email protected]~esm2?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
