Security Advisory

CVE-2017-12132

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2017-08-01 16:00:00
Last updated 2024-08-05 18:28:16
Assigner mitre
State PUBLISHED

Description

The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2.26, when EDNS support is enabled, will solicit large UDP responses from name servers, potentially simplifying off-path DNS spoofing attacks due to IP fragmentation.