Allocation of Resources Without Limits or Throttling
Affecting glibc package, versions *
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2.26, when EDNS support is enabled, will solicit large UDP responses from name servers, potentially simplifying off-path DNS spoofing attacks due to IP fragmentation.
References
CVSS Score
5.9
medium severity
-
Attack VectorNetwork
-
Attack ComplexityHigh
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityNone
-
IntegrityHigh
-
AvailabilityNone
- CVE
- CVE-2017-12132
- CWE
- CWE-770
- Snyk ID
- SNYK-DEBIAN9-GLIBC-356559
- Disclosed
- 01 Aug, 2017
- Published
- 01 Aug, 2017