ZeroHour

CVE-2023-4813

CVSS 3.1
5.9 medium
EPSS
2%p75
Published
()
Modified
Description

A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or SUCCESS=merge.

Vendors
gnuredhatfedoraprojectnetapp
Products
glibc, enterprise linux, enterprise linux eus, enterprise linux for ibm z systems eus s390x, enterprise linux for ibm z systems s390x, enterprise linux for power little endian, enterprise linux for power little endian eus, enterprise linux server aus, enterprise linux server tus, fedora, active iq unified manager, h300s firmware
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.