REDHAT-BUG-947882: Low severity gnu c library (glibc) vulnerability
A stack (frame) overflow flaw, leading to denial of service (application crash), was found in the way getaddrinfo() routine (returning a list of address structures for particular request) of glibc, the collection of GNU libc libraries, processed certain requests. If an application linked against glibc accepted untrusted getaddrinfo() input remotely, a remote attacker could issue a specially-crafted request, which once processed would lead to that application crash.
References: [1] https://bugzilla.novell.com/showbug.cgi?id=813121 [2] http://www.openwall.com/lists/oss-security/2013/04/03/2
Proposed Novell patch: [3] http://bugzillafiles.novell.org/attachment.cgi?id=533210
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-947882?
The severity of REDHAT-BUG-947882 is considered high due to the potential for denial of service resulting from stack overflow.
How do I fix REDHAT-BUG-947882?
To fix REDHAT-BUG-947882, update the GNU glibc to the latest patched version provided by your distribution.
What applications are affected by REDHAT-BUG-947882?
Applications that are linked against the affected versions of GNU glibc are vulnerable to REDHAT-BUG-947882.
What is the nature of the vulnerability in REDHAT-BUG-947882?
REDHAT-BUG-947882 is a stack frame overflow vulnerability in the getaddrinfo() routine of glibc, leading to application crashes.
When was REDHAT-BUG-947882 discovered?
REDHAT-BUG-947882 was reported and documented in April 2013.