IM
IronMonkey Threat Research

CVE-2021-43523 CRITICAL

Published: 2021-11-10 | Last Modified: 2025-05-05 | Status: Modified

Description

In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names returned by DNS servers via gethostbyname, getaddrinfo, gethostbyaddr, and getnameinfo can lead to output of wrong hostnames (leading to domain hijacking) or injection into applications (leading to remote code execution, XSS, applications crashes, etc.). In other words, a validation step, which is expected in any stub resolver, does not occur.

Additional Descriptions (1)

En uClibc y uClibc-ng versiones anteriores a 1.0.39, el manejo incorrecto de los caracteres especiales en los nombres de dominio devueltos por los servidores DNS por medio de gethostbyname, getaddrinfo, gethostbyaddr y getnameinfo puede conllevar a una salida de nombres de host erróneos (conllevando al secuestro de dominios) o una inyección en aplicaciones (conllevando a una ejecución de código remota, un ataque de tipo XSS, bloqueo de aplicaciones, etc.). En otras palabras, un paso de comprobación, que se espera en cualquier stub resolver, no ocurre

CVSS Metrics

Base Score: 9.6 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionREQUIRED
ScopeCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 2.8

Impact Score: 6.0

Base Score: 6.8 (MEDIUM)

AV:N/AC:M/Au:N/C:P/I:P/A:P

Access VectorNETWORK
Access ComplexityMEDIUM
AuthenticationNONE
Confidentiality ImpactPARTIAL
Integrity ImpactPARTIAL
Availability ImpactPARTIAL

Source: [email protected]

Type: Primary

Exploitability Score: 8.6

Impact Score: 6.4

Weaknesses

Source Type Description
[email protected] Primary
en CWE-79
134c704f-9b21-4f2e-91b3-4a467353bcc0 Secondary
en CWE-79

Affected Products

Vendor Product Version Update Type
uclibc uclibc * <built-in method update of dict object at 0x72a9ccf29980> Application
uclibc-ng_project uclibc-ng * <built-in method update of dict object at 0x72a9ccf2b700> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:uclibc:uclibc:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:uclibc-ng_project:uclibc-ng:*:*:*:*:*:*:*:*

References

Notification
Message here