Glibc: potential use-after-free in gaih_inet()
CVE-2023-4813

5.9MEDIUM

Summary

A flaw was found in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or SUCCESS=merge.

Affected Version(s)

Red Hat Enterprise Linux 8 0:2.28-225.el8_8.6

Red Hat Enterprise Linux 8 0:2.28-225.el8_8.6

Red Hat Enterprise Linux 8.6 Extended Update Support 0:2.28-189.8.el8_6

News Articles

glibc - CVE CyberSecurity Database News

CVE CyberSecurity Database News - Latest cybersecurity news and CVE details Sign...

9 months ago

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • πŸ“°

    First article discovered by www.cve.news

  • Vulnerability published

  • Vulnerability Reserved

.