CVE-2014-3484 describes multiple stack-based buffer overflows in the __dn_expand function within musl libc versions 1.1.x before 1.1.2 and 0.9.13 through 1.0.3. This critical vulnerability (CVSS 9.8) allows remote attackers to cause a denial of service (crash) or achieve unspecified impact via an invalid name length in a DNS response, potentially leading to an infinite loop. While there is no evidence of active exploitation, nor publicly available exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community discussion with 10 mentions, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.9.13, <= 1.0.3CPE matchmatch criteria | cpe:2.3:a:musl-libc:musl:*:*:*:*:*:*:*:* | ||
>= 1.1.0, < 1.1.2CPE matchmatch criteria | cpe:2.3:a:musl-libc:musl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.