PT-2015-3583 · Gnu+5 · Glibc+5

Arnaud.Lb

+2

·

Published

2015-02-24

·

Updated

2024-06-15

·

CVE-2013-7423

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions glibc versions prior to 2.20
Description The issue arises from the send dg function in resolv/res send.c, which fails to properly reuse file descriptors. This allows remote attackers to send DNS queries to unintended locations by triggering a large number of requests that call the getaddrinfo function.
Recommendations For versions prior to 2.20, update to version 2.20 or later to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-2084
CESA-2015_0863
CESA-2015_2199
CVE-2013-7423
DLA-165-1
MGASA-2015-0195
OPENSUSE-SU-2024:10154-1
RHSA-2015:0863
RHSA-2015:2199
RHSA-2015:2589
RHSA-2015_0863
RHSA-2015_2199
RHSA-2016:1207
SUSE-RU-2015:0794-1
SUSE-SU-2015:0253-1
SUSE-SU-2015:0439-1
SUSE-SU-2015:0526-1
SUSE-SU-2015:0551-1
SUSE-SU-2015_0439-1
SUSE-SU-2015_0526-1
SUSE-SU-2015_0550-1
SUSE-SU-2015_0551-1
USN-2519-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Glibc