CVE-2017-15650

Source
https://nvd.nist.gov/vuln/detail/CVE-2017-15650
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-15650.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-15650
Related
Published
2017-10-19T23:29:00Z
Modified
2024-09-18T02:45:55.483154Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

musl libc before 1.1.17 has a buffer overflow via crafted DNS replies because dnsparsecallback in network/lookup_name.c does not restrict the number of addresses, and thus an attacker can provide an unexpected number by sending A records in a reply to an AAAA query.

References

Affected packages

Alpine:v3.2 / musl

Package

Name
musl
Purl
pkg:apk/alpine/musl?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.11-r5

Affected versions

0.*

0.9.10-r0
0.9.11-r0
0.9.11-r1
0.9.11-r2
0.9.11-r3
0.9.11-r4
0.9.12-r0
0.9.13-r0
0.9.13-r1
0.9.14-r0
0.9.14-r1
0.9.14-r2
0.9.14-r3
0.9.14-r4
0.9.14-r5
0.9.14-r6
0.9.14-r7
0.9.14-r8
0.9.14-r9
0.9.14-r10
0.9.14-r11
0.9.14-r12
0.9.15-r0
0.9.15-r1
0.9.15-r2
0.9.15-r3
0.9.15-r4

1.*

1.0.0-r0
1.0.0-r1
1.0.0-r2
1.0.0-r3
1.0.0-r4
1.0.0-r5
1.0.0-r6
1.0.0-r7
1.0.0-r8
1.0.0-r9
1.0.0-r10
1.0.0-r11
1.1.0-r0
1.1.0-r1
1.1.0-r2
1.1.0-r3
1.1.0-r4
1.1.0-r5
1.1.0-r6
1.1.0-r7
1.1.1-r0
1.1.1-r1
1.1.1-r2
1.1.1-r3
1.1.2-r0
1.1.2-r1
1.1.2-r2
1.1.2-r3
1.1.2-r4
1.1.2-r5
1.1.3-r0
1.1.3-r1
1.1.3-r2
1.1.3-r3
1.1.3-r4
1.1.3-r5
1.1.4-r0
1.1.4-r1
1.1.4-r2
1.1.4-r3
1.1.4-r4
1.1.4-r5
1.1.4-r6
1.1.4-r7
1.1.4-r8
1.1.5-r0
1.1.5-r1
1.1.5-r2
1.1.5-r3
1.1.5-r4
1.1.6-r0
1.1.7-r0
1.1.7-r1
1.1.7-r2
1.1.8-r0
1.1.8-r1
1.1.9-r0
1.1.9-r1
1.1.9-r2
1.1.9-r3
1.1.9-r4
1.1.9-r5
1.1.11-r2
1.1.11-r3
1.1.11-r4

Alpine:v3.3 / musl

Package

Name
musl
Purl
pkg:apk/alpine/musl?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.12-r8

Affected versions

0.*

0.9.10-r0
0.9.11-r0
0.9.11-r1
0.9.11-r2
0.9.11-r3
0.9.11-r4
0.9.12-r0
0.9.13-r0
0.9.13-r1
0.9.14-r0
0.9.14-r1
0.9.14-r2
0.9.14-r3
0.9.14-r4
0.9.14-r5
0.9.14-r6
0.9.14-r7
0.9.14-r8
0.9.14-r9
0.9.14-r10
0.9.14-r11
0.9.14-r12
0.9.15-r0
0.9.15-r1
0.9.15-r2
0.9.15-r3
0.9.15-r4

1.*

1.0.0-r0
1.0.0-r1
1.0.0-r2
1.0.0-r3
1.0.0-r4
1.0.0-r5
1.0.0-r6
1.0.0-r7
1.0.0-r8
1.0.0-r9
1.0.0-r10
1.0.0-r11
1.1.0-r0
1.1.0-r1
1.1.0-r2
1.1.0-r3
1.1.0-r4
1.1.0-r5
1.1.0-r6
1.1.0-r7
1.1.1-r0
1.1.1-r1
1.1.1-r2
1.1.1-r3
1.1.2-r0
1.1.2-r1
1.1.2-r2
1.1.2-r3
1.1.2-r4
1.1.2-r5
1.1.3-r0
1.1.3-r1
1.1.3-r2
1.1.3-r3
1.1.3-r4
1.1.3-r5
1.1.4-r0
1.1.4-r1
1.1.4-r2
1.1.4-r3
1.1.4-r4
1.1.4-r5
1.1.4-r6
1.1.4-r7
1.1.4-r8
1.1.5-r0
1.1.5-r1
1.1.5-r2
1.1.5-r3
1.1.5-r4
1.1.6-r0
1.1.7-r0
1.1.7-r1
1.1.7-r2
1.1.8-r0
1.1.8-r1
1.1.9-r0
1.1.9-r1
1.1.9-r2
1.1.10-r0
1.1.10-r1
1.1.10-r2
1.1.10-r3
1.1.10-r4
1.1.11-r0
1.1.11-r1
1.1.11-r2
1.1.12-r0
1.1.12-r1
1.1.12-r2
1.1.12-r3
1.1.12-r4
1.1.12-r5
1.1.12-r6
1.1.12-r7

Alpine:v3.4 / musl

Package

Name
musl
Purl
pkg:apk/alpine/musl?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.14-r16

Affected versions

0.*

0.9.10-r0
0.9.11-r0
0.9.11-r1
0.9.11-r2
0.9.11-r3
0.9.11-r4
0.9.12-r0
0.9.13-r0
0.9.13-r1
0.9.14-r0
0.9.14-r1
0.9.14-r2
0.9.14-r3
0.9.14-r4
0.9.14-r5
0.9.14-r6
0.9.14-r7
0.9.14-r8
0.9.14-r9
0.9.14-r10
0.9.14-r11
0.9.14-r12
0.9.15-r0
0.9.15-r1
0.9.15-r2
0.9.15-r3
0.9.15-r4

1.*

1.0.0-r0
1.0.0-r1
1.0.0-r2
1.0.0-r3
1.0.0-r4
1.0.0-r5
1.0.0-r6
1.0.0-r7
1.0.0-r8
1.0.0-r9
1.0.0-r10
1.0.0-r11
1.1.0-r0
1.1.0-r1
1.1.0-r2
1.1.0-r3
1.1.0-r4
1.1.0-r5
1.1.0-r6
1.1.0-r7
1.1.1-r0
1.1.1-r1
1.1.1-r2
1.1.1-r3
1.1.2-r0
1.1.2-r1
1.1.2-r2
1.1.2-r3
1.1.2-r4
1.1.2-r5
1.1.3-r0
1.1.3-r1
1.1.3-r2
1.1.3-r3
1.1.3-r4
1.1.3-r5
1.1.4-r0
1.1.4-r1
1.1.4-r2
1.1.4-r3
1.1.4-r4
1.1.4-r5
1.1.4-r6
1.1.4-r7
1.1.4-r8
1.1.5-r0
1.1.5-r1
1.1.5-r2
1.1.5-r3
1.1.5-r4
1.1.6-r0
1.1.7-r0
1.1.7-r1
1.1.7-r2
1.1.8-r0
1.1.8-r1
1.1.9-r0
1.1.9-r1
1.1.9-r2
1.1.10-r0
1.1.10-r1
1.1.10-r2
1.1.10-r3
1.1.10-r4
1.1.11-r0
1.1.11-r1
1.1.11-r2
1.1.12-r0
1.1.12-r1
1.1.12-r2
1.1.13-r0
1.1.13-r1
1.1.13-r2
1.1.14-r0
1.1.14-r1
1.1.14-r2
1.1.14-r3
1.1.14-r4
1.1.14-r5
1.1.14-r6
1.1.14-r7
1.1.14-r8
1.1.14-r9
1.1.14-r10
1.1.14-r11
1.1.14-r12
1.1.14-r13
1.1.14-r14
1.1.14-r15

Alpine:v3.5 / musl

Package

Name
musl
Purl
pkg:apk/alpine/musl?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.15-r8

Affected versions

0.*

0.9.10-r0
0.9.11-r0
0.9.11-r1
0.9.11-r2
0.9.11-r3
0.9.11-r4
0.9.12-r0
0.9.13-r0
0.9.13-r1
0.9.14-r0
0.9.14-r1
0.9.14-r2
0.9.14-r3
0.9.14-r4
0.9.14-r5
0.9.14-r6
0.9.14-r7
0.9.14-r8
0.9.14-r9
0.9.14-r10
0.9.14-r11
0.9.14-r12
0.9.15-r0
0.9.15-r1
0.9.15-r2
0.9.15-r3
0.9.15-r4

1.*

1.0.0-r0
1.0.0-r1
1.0.0-r2
1.0.0-r3
1.0.0-r4
1.0.0-r5
1.0.0-r6
1.0.0-r7
1.0.0-r8
1.0.0-r9
1.0.0-r10
1.0.0-r11
1.1.0-r0
1.1.0-r1
1.1.0-r2
1.1.0-r3
1.1.0-r4
1.1.0-r5
1.1.0-r6
1.1.0-r7
1.1.1-r0
1.1.1-r1
1.1.1-r2
1.1.1-r3
1.1.2-r0
1.1.2-r1
1.1.2-r2
1.1.2-r3
1.1.2-r4
1.1.2-r5
1.1.3-r0
1.1.3-r1
1.1.3-r2
1.1.3-r3
1.1.3-r4
1.1.3-r5
1.1.4-r0
1.1.4-r1
1.1.4-r2
1.1.4-r3
1.1.4-r4
1.1.4-r5
1.1.4-r6
1.1.4-r7
1.1.4-r8
1.1.5-r0
1.1.5-r1
1.1.5-r2
1.1.5-r3
1.1.5-r4
1.1.6-r0
1.1.7-r0
1.1.7-r1
1.1.7-r2
1.1.8-r0
1.1.8-r1
1.1.9-r0
1.1.9-r1
1.1.9-r2
1.1.10-r0
1.1.10-r1
1.1.10-r2
1.1.10-r3
1.1.10-r4
1.1.11-r0
1.1.11-r1
1.1.11-r2
1.1.12-r0
1.1.12-r1
1.1.12-r2
1.1.13-r0
1.1.13-r1
1.1.13-r2
1.1.14-r0
1.1.14-r1
1.1.14-r2
1.1.14-r3
1.1.14-r4
1.1.14-r5
1.1.14-r6
1.1.14-r7
1.1.14-r8
1.1.14-r9
1.1.14-r10
1.1.14-r11
1.1.15-r0
1.1.15-r1
1.1.15-r2
1.1.15-r3
1.1.15-r4
1.1.15-r5
1.1.15-r6
1.1.15-r7

Alpine:v3.6 / musl

Package

Name
musl
Purl
pkg:apk/alpine/musl?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.16-r14

Affected versions

0.*

0.9.10-r0
0.9.11-r0
0.9.11-r1
0.9.11-r2
0.9.11-r3
0.9.11-r4
0.9.12-r0
0.9.13-r0
0.9.13-r1
0.9.14-r0
0.9.14-r1
0.9.14-r2
0.9.14-r3
0.9.14-r4
0.9.14-r5
0.9.14-r6
0.9.14-r7
0.9.14-r8
0.9.14-r9
0.9.14-r10
0.9.14-r11
0.9.14-r12
0.9.15-r0
0.9.15-r1
0.9.15-r2
0.9.15-r3
0.9.15-r4

1.*

1.0.0-r0
1.0.0-r1
1.0.0-r2
1.0.0-r3
1.0.0-r4
1.0.0-r5
1.0.0-r6
1.0.0-r7
1.0.0-r8
1.0.0-r9
1.0.0-r10
1.0.0-r11
1.1.0-r0
1.1.0-r1
1.1.0-r2
1.1.0-r3
1.1.0-r4
1.1.0-r5
1.1.0-r6
1.1.0-r7
1.1.1-r0
1.1.1-r1
1.1.1-r2
1.1.1-r3
1.1.2-r0
1.1.2-r1
1.1.2-r2
1.1.2-r3
1.1.2-r4
1.1.2-r5
1.1.3-r0
1.1.3-r1
1.1.3-r2
1.1.3-r3
1.1.3-r4
1.1.3-r5
1.1.4-r0
1.1.4-r1
1.1.4-r2
1.1.4-r3
1.1.4-r4
1.1.4-r5
1.1.4-r6
1.1.4-r7
1.1.4-r8
1.1.5-r0
1.1.5-r1
1.1.5-r2
1.1.5-r3
1.1.5-r4
1.1.6-r0
1.1.7-r0
1.1.7-r1
1.1.7-r2
1.1.8-r0
1.1.8-r1
1.1.9-r0
1.1.9-r1
1.1.9-r2
1.1.10-r0
1.1.10-r1
1.1.10-r2
1.1.10-r3
1.1.10-r4
1.1.11-r0
1.1.11-r1
1.1.11-r2
1.1.12-r0
1.1.12-r1
1.1.12-r2
1.1.13-r0
1.1.13-r1
1.1.13-r2
1.1.14-r0
1.1.14-r1
1.1.14-r2
1.1.14-r3
1.1.14-r4
1.1.14-r5
1.1.14-r6
1.1.14-r7
1.1.14-r8
1.1.14-r9
1.1.14-r10
1.1.14-r11
1.1.15-r0
1.1.15-r1
1.1.15-r2
1.1.15-r3
1.1.15-r4
1.1.15-r5
1.1.15-r6
1.1.16-r0
1.1.16-r1
1.1.16-r2
1.1.16-r3
1.1.16-r4
1.1.16-r5
1.1.16-r6
1.1.16-r7
1.1.16-r8
1.1.16-r9
1.1.16-r10
1.1.16-r11
1.1.16-r12
1.1.16-r13

Debian:11 / musl

Package

Name
musl
Purl
pkg:deb/debian/musl?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.17-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / musl

Package

Name
musl
Purl
pkg:deb/debian/musl?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.17-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / musl

Package

Name
musl
Purl
pkg:deb/debian/musl?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.17-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}