Critical severity9.6NVD Advisory· Published Nov 10, 2021· Updated Jun 17, 2026
CVE-2021-43523
CVE-2021-43523
Description
In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names returned by DNS servers via gethostbyname, getaddrinfo, gethostbyaddr, and getnameinfo can lead to output of wrong hostnames (leading to domain hijacking) or injection into applications (leading to remote code execution, XSS, applications crashes, etc.). In other words, a validation step, which is expected in any stub resolver, does not occur.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- uClibc/uClibc-ngdescription
Patches
Vulnerability mechanics
References
3- github.com/wbx-github/uclibc-ng/commit/0f822af0445e5348ce7b7bd8ce1204244f31d174nvdPatchThird Party Advisory
- www.openwall.com/lists/oss-security/2021/11/09/1nvdExploitMailing ListThird Party Advisory
- uclibc-ng.orgnvdVendor Advisory
News mentions
0No linked articles in our index yet.