USN-6409-1: GNU C Library vulnerabilities
It was discovered that the GNU C Library incorrectly handled the GLIBCTUNABLES environment variable. An attacker could possibly use this issue to perform a privilege escalation attack. (CVE-2023-4911) It was discovered that the GNU C Library incorrectly handled certain DNS responses when the system was configured in no-aaaa mode. A remote attacker could possibly use this issue to cause the GNU C Library to crash, resulting in a denial of service. This issue only affected Ubuntu 23.04. (CVE-2023-4527)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for these GNU C Library vulnerabilities?
The vulnerability ID for these GNU C Library vulnerabilities is CVE-2023-4911.
What is the impact of CVE-2023-4911?
CVE-2023-4911 could allow an attacker to perform a privilege escalation attack.
Which software packages are affected by these vulnerabilities?
The GNU C Library vulnerabilities affect the libc6 package with versions 2.37-0ubuntu2.1 and 2.35-0ubuntu3.4 on Ubuntu 23.04 and 22.04, respectively.
How can I fix the GNU C Library vulnerabilities?
To fix the GNU C Library vulnerabilities, update the libc6 package to versions 2.37-0ubuntu2.1 or 2.35-0ubuntu3.4, depending on your Ubuntu version.
Where can I find more information about these vulnerabilities?
More information about these vulnerabilities can be found at the following references: [CVE-2023-4911](https://ubuntu.com/security/CVE-2023-4911) and [CVE-2023-4527](https://ubuntu.com/security/CVE-2023-4527).