CVE-2014-9402
The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2.21, when the DNS backend in the Name Service Switch configuration is enabled, allows remote attackers to cause a denial of service (infinite loop) by sending a positive answer while a network name is being process.
- Gnu Glibc
- ≤ 2.20
- Fix
- Available
- CVSS 2.0
- 7.8 HIGH
- EPSS
- 7.8% (94th percentile)
- Weakness
- CWE-399
- NVD status
- Modified
- Published
- 2015-02-24
CVE-2014-9402 at NVD
2 known exploits for CVE-2014-9402
Proof-of-concept code and exploit modules indexed by Sploitus