CVE-2014-3484: Buffer Overflow
Last updated 24 July 2024
Other sources
Multiple stack-based buffer overflows in the dnexpand function in network/dnexpand.c in musl libc 1.1x before 1.1.2 and 0.9.13 through 1.0.3 allow remote attackers to (1) have unspecified impact via an invalid name length in a DNS response or (2) cause a denial of service (crash) via an invalid name length in a DNS response, related to an infinite loop with no output.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3484?
The severity of CVE-2014-3484 is critical with a severity value of 9.8.
What is the affected software for CVE-2014-3484?
The affected software for CVE-2014-3484 is musl libc versions 0.9.13 through 1.0.3 and versions 1.1.0 through 1.1.2.
How can remote attackers exploit CVE-2014-3484?
Remote attackers can exploit CVE-2014-3484 by causing a denial of service (crash) via an invalid DNS response or by having unspecified impact through an invalid name length in a DNS response.
What is the remedy for CVE-2014-3484 on Ubuntu?
The remedy for CVE-2014-3484 on Ubuntu is to update musl libc to version 0.9.15-1ubuntu0.1~ or higher.
What is the remedy for CVE-2014-3484 on Debian?
The remedy for CVE-2014-3484 on Debian is to update musl libc to version 1.1.21-2, 1.2.2-1, or 1.2.3-1.