PT-2015-3584 · Gnu+1 · Glibc+1

Chris Hills

·

Published

2014-10-13

·

Updated

2016-11-28

·

CVE-2013-7424

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions glibc versions prior to 2.15
Description The issue allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors, as demonstrated by an internationalized domain name to ping6. This is related to the getaddrinfo function when compiled with libidn and the AI IDN flag is used.
Recommendations For versions prior to 2.15, update to version 2.15 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the AI IDN flag with the getaddrinfo function until a patch is available.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-7424
DLA-165-1
DSA-3169-1
RHSA-2014:1391
RHSA-2014_1391
RHSA-2015:1627
RHSA-2015_1627

Affected Products

Red Hat
Glibc