CVE-2023-4813

EUVD-2023-54657
A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or SUCCESS=merge.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
redhatCNA
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 53%
Affected Products (NVD)
VendorProductVersion
gnuglibc
𝑥
< 2.36
redhatenterprise_linux
8.0
redhatenterprise_linux
9.0
redhatenterprise_linux_eus
8.8
redhatenterprise_linux_eus
9.2
redhatenterprise_linux_for_ibm_z_systems_eus_s390x
9.2
redhatenterprise_linux_for_ibm_z_systems_s390x
9.2
redhatenterprise_linux_for_power_little_endian
9.2_ppc64le:_ppc64le
redhatenterprise_linux_for_power_little_endian_eus
9.2_ppc64le:_ppc64le
redhatenterprise_linux_server_aus
9.2
redhatenterprise_linux_server_tus
8.8
netappactive_iq_unified_manager
-
netapph300s_firmware
-
netapph500s_firmware
-
netapph700s_firmware
-
netapph410s_firmware
-
netapph410c_firmware
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
glibc
bookworm
2.36-9+deb12u9
fixed
bookworm (security)
2.36-9+deb12u7
fixed
bullseye
no-dsa
bullseye (security)
vulnerable
buster
no-dsa
sid
2.40-4
fixed
trixie
2.40-4
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
eglibc
bionic
dne
focal
dne
jammy
dne
lunar
dne
mantic
dne
noble
dne
oracular
dne
trusty
ignored
xenial
dne
glibc
bionic
Fixed 2.27-3ubuntu1.6+esm1
released
focal
Fixed 2.31-0ubuntu9.14
released
jammy
Fixed 2.35-0ubuntu3.5
released
lunar
not-affected
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
ignored
xenial
Fixed 2.23-0ubuntu11.3+esm5
released