Candidate: CVE-2014-3484 PublicDate: 2020-02-20 04:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3484 https://marc.info/?l=oss-security&m=140210606626487&w=2 Description: Multiple stack-based buffer overflows in the __dn_expand function in network/dn_expand.c in musl libc 1.1x before 1.1.2 and 0.9.13 through 1.0.3 allow remote attackers to (1) have unspecified impact via an invalid name length in a DNS response or (2) cause a denial of service (crash) via an invalid name length in a DNS response, related to an infinite loop with no output. Ubuntu-Description: It was discovered that musl did not properly handle the parsing of DNS response codes. An remote attacker could use this vulnerability to cause resource consumption (infinite loop), denial of service, or possibly execute arbitrary code. Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=750815 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_musl: upstream: http://git.musl-libc.org/cgit/musl/commit/?id=b3d9e0b94ea73c68ef4169ec82c898ce59a4e30a upstream_musl: released (1.0.3 and 1.1.2) lucid_musl: DNE precise_musl: DNE precise/esm_musl: DNE saucy_musl: DNE trusty_musl: ignored (reached end-of-life) trusty/esm_musl: DNE (trusty was needed) utopic_musl: ignored (reached end-of-life) vivid_musl: not-affected (1.1.4-1) vivid/stable-phone-overlay_musl: DNE vivid/ubuntu-core_musl: DNE wily_musl: not-affected (1.1.4-1) xenial_musl: not-affected (1.1.4-1) yakkety_musl: not-affected (1.1.4-1) zesty_musl: not-affected (1.1.4-1) artful_musl: not-affected (1.1.4-1) bionic_musl: not-affected (1.1.4-1) cosmic_musl: not-affected (1.1.4-1) disco_musl: not-affected (1.1.4-1) devel_musl: not-affected (1.1.4-1)