The send_dg function in resolv/res_send.c in GNU C Library (aka glibc or libc6) before 2.20 does not properly reuse file descriptors, which allows remote attackers to send DNS queries to unintended locations via a large number of requests that trigger a call to the getaddrinfo function.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Enterprise_linux_server_aus | Redhat | 6.5 (including) | 6.5 (including) |
Eglibc | Ubuntu | lucid | * |
Eglibc | Ubuntu | precise | * |
Eglibc | Ubuntu | trusty | * |
Red Hat Enterprise Linux 6 | RedHat | glibc-0:2.12-1.149.el6_6.7 | * |
Red Hat Enterprise Linux 6.5 Advanced Update Support | RedHat | glibc-0:2.12-1.132.el6_5.8 | * |
Red Hat Enterprise Linux 7 | RedHat | glibc-0:2.17-105.el7 | * |
Red Hat Enterprise Linux 7.1 Extended Update Support | RedHat | glibc-0:2.17-79.ael7b_1 | * |