Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-7424

Опубликовано: 26 авг. 2015
Источник: debian
EPSS Низкий

Описание

The getaddrinfo function in glibc before 2.15, when compiled with libidn and the AI_IDN flag is used, allows context-dependent attackers to cause a denial of service (invalid free) and possibly execute arbitrary code via unspecified vectors, as demonstrated by an internationalized domain name to ping6.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
glibcfixed2.15-1package
eglibcfixed2.15-1package

Примечания

  • http://seclists.org/oss-sec/2015/q1/306

  • Upstream fix: https://sourceware.org/git/gitweb.cgi?p=glibc.git;a=commitdiff;h=2e96f1c7

  • https://bugzilla.redhat.com/show_bug.cgi?id=981942

EPSS

Процентиль: 74%
0.00831
Низкий

Связанные уязвимости

ubuntu
больше 10 лет назад

The getaddrinfo function in glibc before 2.15, when compiled with libidn and the AI_IDN flag is used, allows context-dependent attackers to cause a denial of service (invalid free) and possibly execute arbitrary code via unspecified vectors, as demonstrated by an internationalized domain name to ping6.

redhat
около 11 лет назад

The getaddrinfo function in glibc before 2.15, when compiled with libidn and the AI_IDN flag is used, allows context-dependent attackers to cause a denial of service (invalid free) and possibly execute arbitrary code via unspecified vectors, as demonstrated by an internationalized domain name to ping6.

nvd
больше 10 лет назад

The getaddrinfo function in glibc before 2.15, when compiled with libidn and the AI_IDN flag is used, allows context-dependent attackers to cause a denial of service (invalid free) and possibly execute arbitrary code via unspecified vectors, as demonstrated by an internationalized domain name to ping6.

github
больше 3 лет назад

The getaddrinfo function in glibc before 2.15, when compiled with libidn and the AI_IDN flag is used, allows context-dependent attackers to cause a denial of service (invalid free) and possibly execute arbitrary code via unspecified vectors, as demonstrated by an internationalized domain name to ping6.

oracle-oval
больше 10 лет назад

ELSA-2015-1627: glibc security update (MODERATE)

EPSS

Процентиль: 74%
0.00831
Низкий