CVE-2017-12132: Medium severity GNU glibc vulnerability
Last updated 24 July 2024
Other sources
The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2.26, when EDNS support is enabled, will solicit large UDP responses from name servers, potentially simplifying off-path DNS spoofing attacks due to IP fragmentation.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12132?
CVE-2017-12132 is classified as having high severity due to its potential to facilitate DNS spoofing attacks.
How do I fix CVE-2017-12132?
To fix CVE-2017-12132, upgrade the GNU C Library to version 2.26 or higher.
Which software is affected by CVE-2017-12132?
CVE-2017-12132 affects versions of the GNU C Library before 2.26 and specifically those with EDNS support enabled.
Can CVE-2017-12132 lead to data breaches?
Yes, CVE-2017-12132 could potentially lead to data breaches through successful off-path DNS spoofing.
Is CVE-2017-12132 still a concern in modern systems?
CVE-2017-12132 remains a concern for systems using outdated versions of glibc prior to 2.26 that have not been patched.