CRITICAL 9.6 Microsoft
CVE-2021-43523
In uClibc and uClibc-ng before 1.0.39 incorrect handling of special characters in domain names returned by DNS servers via gethostbyname getaddrinfo gethostbyaddr and getnameinfo can lead to output of wrong hostnames (leading to domain hijacking) or injection into applications (leading to remote code execution XSS applications crashes etc.). In other words a validation step which is expected in any stub resolver does not occur.
Microsoft Security Update 2021-Nov: In uClibc and uClibc-ng before 1.0.39 incorrect handling of special characters in domain names returned by DNS servers via gethostbyname getaddrinfo gethostbyaddr and getnameinfo can lead to output of wrong hostnames (leading to domain hijacking) or injection into applications (leading to remote code execution XSS applications crashes etc.). In other words a validation step which is expected in any stub resolver does not occur.
Affected Products
- cm1 uclibc-ng 1.0.37-2 on CBL Mariner 1.0
- cbl2 uclibc-ng 1.0.37-2 on CBL Mariner 2.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-43523
- https://nvd.nist.gov/vuln/detail/CVE-2021-43523
This critical severity vulnerability with a CVSS score of 9.6 was published on 2021-11-09 via Microsoft. Affected: cm1 uclibc-ng 1.0.37-2 on CBL Mariner 1.0, cbl2 uclibc-ng 1.0.37-2 on CBL Mariner 2.0.
Risk Timeline
CVE Disclosed2021-11-09 · 1745 days ago
Remediation Resources
Official Advisory
msrc.microsoft.com/update-guide/vulnerability/CVE-2021-43523NVD / MITRE
nvd.nist.gov/vuln/detail/CVE-2021-43523Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2021-43267 PoC | An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. | CRITICAL | 9.8 |
| CVE-2023-25725 PoC | HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers | CRITICAL | 9.1 |
| CVE-2020-25632 | A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation al | HIGH | 8.2 |
| CVE-2021-3935 | When PgBouncer is configured to use "cert" authentication a man-in-the-middle at | HIGH | 8.1 |
| CVE-2021-3968 | Heap-based Buffer Overflow in vim/vim | HIGH | 8.0 |
| CVE-2020-12657 | An issue was discovered in the Linux kernel before 5.6.5. There is a use-after-f | HIGH | 7.8 |
vulnfeed aggregates 11644 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.