First published: Fri Mar 24 2017(Updated: )
The __read_etc_hosts_r function in libc/inet/resolv.c in uClibc-ng before 1.0.12 allows remote DNS servers to cause a denial of service (infinite loop) via a crafted packet.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Uclibc-ng Project Uclibc-ng | <=1.0.11 | |
debian/uclibc | 1.0.35-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2225 has a severity rating that indicates a potential denial of service vulnerability due to an infinite loop.
To fix CVE-2016-2225, update to uClibc-ng version 1.0.12 or later.
CVE-2016-2225 affects uClibc-ng versions prior to 1.0.12.
CVE-2016-2225 is categorized as a denial of service vulnerability.
Yes, CVE-2016-2225 can be exploited by remote DNS servers sending crafted packets.