REDHAT-BUG-2430201: Medium severity GNU C Library vulnerability
Calling getnetbyaddr or getnetbyaddrr with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2430201?
The severity of REDHAT-BUG-2430201 is classified as a potential information disclosure vulnerability.
How do I fix REDHAT-BUG-2430201?
To fix REDHAT-BUG-2430201, upgrade your GNU C Library to a version above 2.42.
What versions of the GNU C Library are affected by REDHAT-BUG-2430201?
REDHAT-BUG-2430201 affects GNU C Library versions from 2.0 to 2.42.
What types of queries can lead to the vulnerability REDHAT-BUG-2430201?
Queries for a zero-valued network can lead to the vulnerability REDHAT-BUG-2430201 when using the DNS backend specified in nsswitch.conf.
What could be the impact of exploiting REDHAT-BUG-2430201?
Exploiting REDHAT-BUG-2430201 could lead to the leakage of stack contents to the configured DNS resolver.