CVE-2014-8121
27.03.2015, 14:59
DB_LOOKUP in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) 2.21 and earlier does not properly check if a file is open, which allows remote attackers to cause a denial of service (infinite loop) by performing a look-up on a database while iterating over it, which triggers the file pointer to be reset.Enginsight
| Vendor | Product | Version |
|---|---|---|
| suse | suse_linux_enterprise_server | 11.0:sp3 |
| suse | suse_linux_enterprise_server | 11.0:sp3 |
| suse | suse_linux_enterprise_server | 11.0:sp4 |
| gnu | glibc | 𝑥 ≤ 2.21 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 15.10 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| eglibc |
| ||||||||||||||||||
| glibc |
|
Common Weakness Enumeration
References