Glibc: potential use-after-free in gaih_inet()
CVE-2023-4813
5.9MEDIUM
Summary
A flaw was found in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or SUCCESS=merge.
Affected Version(s)
Red Hat Enterprise Linux 8 0:2.28-225.el8_8.6
Red Hat Enterprise Linux 8 0:2.28-225.el8_8.6
Red Hat Enterprise Linux 8.6 Extended Update Support 0:2.28-189.8.el8_6
Get notified when SecurityVulnerability.io launches alerting π
Well keep you posted π§
News Articles
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
- π°
First article discovered by www.cve.news
Vulnerability published
Vulnerability Reserved