USN-4768-1
Dashboard / Vulnerabilities / USN-4768-1
USN-4768-1
Summary: musl vulnerabilities
Details: It was discovered that musl did not properly handle kernel syscalls. An attacker could use this vulnerability to cause a denial of service (crash) or possibly execute arbitrary code. (CVE-2018-1000001) It was discovered that musl did not properly handle the parsing of DNS response codes. A remote attacker could use this vulnerability to cause resource consumption (infinite loop), denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 14.04 ESM. (CVE-2014-3484) It was discovered that musl did not properly handle the parsing of DNS response codes. A remote attacker could use this vulnerability to cause resource consumption (infinite loop), denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 16.04 ESM. (CVE-2017-15650) It was discovered that musl did not properly handle the parsing of ipv6 addresses. An attacker could use this vulnerability to cause a denial of service (crash) or possibly execute arbitrary code. This issue only affected Ubuntu 14.04 ESM. (CVE-2015-1817) It was discovered that TRE library, used by musl, did not properly handle certain inputs. An attacker could use this vulnerability to cause a denial of service (crash). (CVE-2016-8859)
References: https://ubuntu.com/security/notices/USN-4768-1, https://ubuntu.com/security/CVE-2014-3484, https://ubuntu.com/security/CVE-2015-1817, https://ubuntu.com/security/CVE-2016-8859, https://ubuntu.com/security/CVE-2017-15650, https://ubuntu.com/security/CVE-2018-1000001
Affected packages
Package
Name: musl
Purl: pkg:deb/ubuntu/musl?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
