CVE-2023-4813

CVSS 3.1 Score 5.9 of 10 (medium)

Details

Published Sep 12, 2023
Updated: Jan 21, 2024
CWE ID 416

Summary

CVE-2023-4813 is a vulnerability affecting the glibc library. In an unusual scenario, the gaih_inet function may access memory that has already been freed, leading to an application crash. This issue can only be exploited when the getaddrinfo function is invoked and the hosts database in /etc/nsswitch.conf is configured with specific settings (SUCCESS=continue or SUCCESS=merge).

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Gnu Glibc
  • Red Hat Enterprise Linux
  • Fedora Operating System

Affected Vendors

  • Red Hat
  • Fedora Project
  • NetApp