CVE-2014-9402

Publication date 24 February 2015

Last updated 24 July 2024


Ubuntu priority

The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2.21, when the DNS backend in the Name Service Switch configuration is enabled, allows remote attackers to cause a denial of service (infinite loop) by sending a positive answer while a network name is being process.

Read the notes from the security team

Status

Package Ubuntu Release Status
eglibc 14.10 utopic Not in release
14.04 LTS trusty
Fixed 2.19-0ubuntu6.6
12.04 LTS precise
Fixed 2.15-0ubuntu10.11
10.04 LTS lucid
Fixed 2.11.1-0ubuntu7.21
glibc 14.10 utopic
Fixed 2.19-10ubuntu2.3
14.04 LTS trusty Not in release
12.04 LTS precise Not in release
10.04 LTS lucid Not in release

Notes


mdeslaur

fixed by any/cvs-getnetbyname.diff in vivid

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
glibc

References

Related Ubuntu Security Notices (USN)

    • USN-2519-1
    • GNU C Library vulnerabilities
    • 26 February 2015

Other references