Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2023-4527

A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash.

  • Published: Sep 18, 2023
  • Updated: May 10, 2024
  • CVE: CVE-2023-4527
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 6.5
  • AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H

CWEs:

Software From Fixed in
redhat / enterprise_linux 8.0 8.0.x
redhat / enterprise_linux 9.0 9.0.x
redhat / enterprise_linux_eus 8.8 8.8.x
redhat / enterprise_linux_server_aus 9.2 9.2.x
redhat / enterprise_linux_eus 9.2 9.2.x
redhat / enterprise_linux_for_power_little_endian 9.2_ppc64le 9.2_ppc64le.x
redhat / enterprise_linux_for_power_little_endian_eus 9.2_ppc64le 9.2_ppc64le.x
redhat / enterprise_linux_for_ibm_z_systems_s390x 9.2 9.2.x
redhat / enterprise_linux_for_ibm_z_systems_eus_s390x 9.2 9.2.x
redhat / enterprise_linux_tus 8.8 8.8.x
redhat / codeready_linux_builder_for_arm64_eus 9.2_aarch64 9.2_aarch64.x
redhat / codeready_linux_builder_for_ibm_z_systems_eus 9.2_s390x 9.2_s390x.x
redhat / codeready_linux_builder_eus_for_power_little_endian 9.0_ppc64le 9.0_ppc64le.x
redhat / codeready_linux_builder_for_ibm_z_systems 9.0_s390x 9.0_s390x.x
redhat / codeready_linux_builder_for_arm64 9.0_aarch64 9.0_aarch64.x
redhat / codeready_linux_builder_eus_for_power_little_endian_eus 9.2_ppc64le 9.2_ppc64le.x
redhat / codeready_linux_builder_eus 9.2 9.2.x
redhat / enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions 9.2_ppc64le 9.2_ppc64le.x
redhat / enterprise_linux_for_arm_64_eus 9.2_aarch64 9.2_aarch64.x
redhat / enterprise_linux_for_arm_64 9.0_aarch64 9.0_aarch64.x
redhat / enterprise_linux_for_power_little_endian 8.0_ppc64le 8.0_ppc64le.x
redhat / enterprise_linux_for_power_little_endian_eus 8.8_ppc64le 8.8_ppc64le.x
redhat / enterprise_linux_for_ibm_z_systems_eus 8.8_s390x 8.8_s390x.x
redhat / enterprise_linux_for_ibm_z_systems 8.0_s390x 8.0_s390x.x
fedoraproject / fedora 37 37.x
fedoraproject / fedora 38 38.x
fedoraproject / fedora 39 39.x
gnu / glibc 2.36 2.36.113
gnu / glibc 2.37 2.37.38
gnu / glibc 2.38 2.38.19