Resource exhaustion in GNU C Library (glibc) - CVE-2018-19591
Published: November 28, 2018 / Updated: November 28, 2018
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to an invalid 'ifname' parameter to __if_nametoindex() in 'sysdeps/unix/sysv/linux/if_index.c'. A remote attacker can invoke a call to the getaddrinfo() function with a 'node' parameter, consume excessive memory and cause the service to crash.
Affected software
Gentoo Linux
Ubuntu
Fedora
Netcool Operations Insight
IBM Cloud Transformation Advisor
libc6 (Ubuntu package)
glibc
How to mitigate CVE-2018-19591
Netcool Operations Insight - update to 1.6.8
libc6 (Ubuntu package) - addressed in versions 2.23-0ubuntu11.2, 2.27-3ubuntu1.2, 2.30-0ubuntu2.2
glibc - addressed in versions 2.26-32.fc27, 2.27-35.fc28, 2.28-22.fc29
IBM Cloud Transformation Advisor - update to 3.10.0
External References
Related Security Bulletins
- Denial of service in GNU Glibc
- Gentoo update for GNU C Library
- Gentoo update for glibc
- Multiple vulnerabilities in IBM Netcool Operations Insight
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Ubuntu update for glibc
- Fedora 27 update for glibc
- Fedora 28 update for glibc
- Fedora 29 update for glibc