Gnu c Library getaddrinfo function Stack Buffer Overflow Vulnerability (CVE-2016-3706)
Gnu c Library getaddrinfo function Stack Buffer Overflow Vulnerability (CVE-2016-3706)
Release date:
Updated on:
Affected Systems:
Gnu c Library (glibc)
Description:
CVE (CAN) ID: CVE-2016-3706
Glibc is the libc library released by GNU, that is, the c Runtime Library.
The gnu c Library (glibc or libc6) sysdeps/posix/getaddrinfo. c/getaddrinfo function has the stack buffer overflow vulnerability. Remote attackers can use the hostent conversion to cause DoS attacks.
<* Source: Florian Weimer
*>
Suggestion:
Vendor patch:
GNU
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://sourceware.org/git/gitweb.cgi? P = glibc. git; h = 4ab2ab03d4351914ee53248dc5aef4a8c88ff8b9
Https://sourceware.org/bugzilla/show_bug.cgi? Id = 20010
Upgrade Glibc in Linux
Dangerous! GHOST (GHOST) vulnerability exposure
GNU glibc gethostbyname Buffer Overflow Vulnerability
Glibc gethostbyname Buffer Overflow Vulnerability (CVE-2015-0235)
Linux glibc ghost vulnerability test and repair methods