CRITICAL 9.6 Microsoft

CVE-2021-43523

In uClibc and uClibc-ng before 1.0.39 incorrect handling of special characters in domain names returned by DNS servers via gethostbyname getaddrinfo gethostbyaddr and getnameinfo can lead to output of wrong hostnames (leading to domain hijacking) or injection into applications (leading to remote code execution XSS applications crashes etc.). In other words a validation step which is expected in any stub resolver does not occur.

Microsoft Security Update 2021-Nov: In uClibc and uClibc-ng before 1.0.39 incorrect handling of special characters in domain names returned by DNS servers via gethostbyname getaddrinfo gethostbyaddr and getnameinfo can lead to output of wrong hostnames (leading to domain hijacking) or injection into applications (leading to remote code execution XSS applications crashes etc.). In other words a validation step which is expected in any stub resolver does not occur.

Affected Products

References

Published: 2021-11-09 · Source: Microsoft · Feed updated: 2026-08-20
This critical severity vulnerability with a CVSS score of 9.6 was published on 2021-11-09 via Microsoft. Affected: cm1 uclibc-ng 1.0.37-2 on CBL Mariner 1.0, cbl2 uclibc-ng 1.0.37-2 on CBL Mariner 2.0.

Risk Timeline

CVE Disclosed2021-11-09 · 1745 days ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2021-43267 PoCAn issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16.CRITICAL9.8
CVE-2023-25725 PoCHAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headersCRITICAL9.1
CVE-2020-25632A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation alHIGH8.2
CVE-2021-3935When PgBouncer is configured to use "cert" authentication a man-in-the-middle atHIGH8.1
CVE-2021-3968Heap-based Buffer Overflow in vim/vimHIGH8.0
CVE-2020-12657An issue was discovered in the Linux kernel before 5.6.5. There is a use-after-fHIGH7.8
vulnfeed aggregates 11644 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.