CVE-2023-4813

Updated: 2024-05-15 00:36:24.046459

Description:

A flaw was found in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or SUCCESS=merge.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x MEDIUM 5.9

Status

OS name Project name Version Score Severity Status Errata Last updated
AlmaLinux 9.2 ESU glibc 2.34 5.9 MEDIUM Ignored 2023-11-08 04:08:03
CentOS 6 ELS glibc 2.12 5.9 MEDIUM Ignored 2023-09-21 05:07:19
CentOS 7 ELS glibc 2.17 5.9 MEDIUM Ignored 2023-09-21 05:07:19
CentOS 8.4 ELS glibc 2.28 5.9 MEDIUM In Progress 2024-05-17 10:20:53
CentOS 8.5 ELS glibc 2.28 5.9 MEDIUM In Progress 2024-05-17 10:20:53
CloudLinux 6 ELS glibc 2.12 5.9 MEDIUM Ignored 2023-09-21 05:07:18
Oracle Linux 6 ELS glibc 2.12 5.9 MEDIUM Ignored 2023-09-21 05:07:19
Ubuntu 16.04 ELS glibc 2.23-0 5.9 MEDIUM Released CLSA-2024:1709562366 2024-03-04 10:14:58
Ubuntu 18.04 ELS glibc 2.27-3 5.9 MEDIUM Released CLSA-2024:1708638685 2024-02-22 20:58:55