漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
gethostbyaddr and gethostbyaddr_r may incorrectly handle DNS response
Vulnerability Description
Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server, result in a violation of the DNS specification that causes the application to treat a non-answer section of the DNS response as a valid answer.
CVSS Information
N/A
Vulnerability Type
跨界内存读
Vulnerability Title
GNU C Library 安全漏洞
Vulnerability Description
GNU C Library是GNU社区的一种按照LGPL许可协议发布的开源免费的C语言编译程序。 GNU C Library 2.34至2.43版本存在安全漏洞,该漏洞源于gethostbyaddr或gethostbyaddr_r函数可能将DNS响应的非答案部分视为有效答案,违反DNS规范。
CVSS Information
N/A
Vulnerability Type
N/A