CVE-2018-19591
Summary
| CVE | CVE-2018-19591 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-12-04 16:29:00 UTC |
| Updated | 2023-11-07 02:55:00 UTC |
| Description | In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to the if_nametoindex() function. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| GNU C Library: Arbitrary descriptor allocation (GLSA 201903-09) — Gentoo security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| sourceware.org/git |
CONFIRM |
sourceware.org |
Release Notes, Third Party Advisory |
| sourceware.org Git - glibc.git/commitdiff |
|
sourceware.org |
|
| sourceware.org Git |
|
sourceware.org |
|
| Glibc if_nametoindex() Socket Descriptor State Error Lets Remote Users Consume Excessive Memory Resources - SecurityTracker |
SECTRACK |
www.securitytracker.com |
Third Party Advisory, VDB Entry |
| [SECURITY] Fedora 28 Update: glibc-2.27-35.fc28 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Patch, Third Party Advisory |
| glibc: Multiple vulnerabilities (GLSA 201908-06) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| Malformed Request |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| [SECURITY] Fedora 29 Update: glibc-2.28-22.fc29 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Third Party Advisory |
| 23927 – (CVE-2018-19591) Linux if_nametoindex() does not close descriptor (CVE-2018-19591) |
CONFIRM |
sourceware.org |
Exploit, Issue Tracking, Third Party Advisory |
| [SECURITY] Fedora 29 Update: glibc-2.28-22.fc29 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 28 Update: glibc-2.27-35.fc28 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| USN-4416-1: GNU C Library vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
|
| sourceware.org Git - glibc.git/commitdiff |
CONFIRM |
sourceware.org |
Mailing List, Patch, Third Party Advisory |
| CVE-2018-19591 GNU C Library (glibc) Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 591406 Siemens SIMATIC S7-1500 CPU GNU/Linux subsystem Multiple Vulnerabilities (SSB-439005, ICSA-22-104-13)
- 710153 Gentoo Linux glibc Multiple vulnerabilities (GLSA 201908-06)
- 710199 Gentoo Linux GNU C Library Arbitrary descriptor allocation Vulnerability (GLSA 201903-09)
- 900018 CBL-Mariner Linux Security Update for glibc 2.28
- 903167 Common Base Linux Mariner (CBL-Mariner) Security Update for glibc (1941)