CVE-2014-8121
Publication date 27 March 2015
Last updated 24 July 2024
Ubuntu priority
DB_LOOKUP in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) 2.21 and earlier does not properly check if a file is open, which allows remote attackers to cause a denial of service (infinite loop) by performing a look-up on a database while iterating over it, which triggers the file pointer to be reset.
From the Ubuntu Security Team
Robin Hack discovered that the Name Service Switch (NSS) implementation in the GNU C Library did not properly manage its file descriptors. An attacker could use this to cause a denial of service (infinite loop).
Status
Package | Ubuntu Release | Status |
---|---|---|
eglibc | ||
16.04 LTS xenial | Not in release | |
14.04 LTS trusty |
Fixed 2.19-0ubuntu6.8
|
|
glibc | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release | |
Patch details
Package | Patch details |
---|---|
glibc |
References
Related Ubuntu Security Notices (USN)
- USN-2985-1
- GNU C Library vulnerabilities
- 25 May 2016