Medium severity5.9NVD Advisory· Published Aug 1, 2017· Updated May 13, 2026
CVE-2017-12132
CVE-2017-12132
Description
The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2.26, when EDNS support is enabled, will solicit large UDP responses from name servers, potentially simplifying off-path DNS spoofing attacks due to IP fragmentation.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- arxiv.org/pdf/1205.4011.pdfnvdTechnical DescriptionThird Party Advisory
- www.securityfocus.com/bid/100598nvd
- access.redhat.com/errata/RHSA-2018:0805nvd
News mentions
0No linked articles in our index yet.