Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in the GNU C Library (aka glibc or libc6) allows remote attackers to cause a denial of service (crash) via vectors involving hostent conversion. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4458.
References
Configurations
History
No history.
Information
Published : 2016-06-10 15:59
Updated : 2025-04-12 10:46
NVD link : CVE-2016-3706
Mitre link : CVE-2016-3706
CVE.ORG link : CVE-2016-3706
JSON object : View
Products Affected
opensuse
- opensuse
gnu
- glibc
CWE
CWE-20
Improper Input Validation