CVE-2017-12133: Use After Free
Published Sep 7, 2017
·Updated
Last updated 24 July 2024
Other sources
Use-after-free vulnerability in the clntudpcall function in sunrpc/clntudp.c in the GNU C Library (aka glibc or libc6) before 2.26 allows remote attackers to have unspecified impact via vectors related to error path.
Affected Software
2 affected componentsFixes available
GNU glibc<=2.25
debian/glibc
2.31-13+deb11u112.31-13+deb11u122.36-9+deb12u102.36-9+deb12u72.41-7
Remediation
Event History
Sep 7, 2017
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:26 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:18 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2017-12133.
2
What is the severity level of CVE-2017-12133?
CVE-2017-12133 has a severity level of medium.
3
What is the affected software for CVE-2017-12133?
The affected software for CVE-2017-12133 is GNU glibc version up to and including 2.25.
4
How can remote attackers exploit CVE-2017-12133?
Remote attackers can exploit CVE-2017-12133 through vectors related to the error path.
5
Are there any fixes or remedies available for CVE-2017-12133?
Yes, fixes and remedies are available for CVE-2017-12133. Please refer to the references for more information.