Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-7424

Опубликовано: 27 янв. 2015
Источник: redhat
CVSS2: 5.1

Описание

The getaddrinfo function in glibc before 2.15, when compiled with libidn and the AI_IDN flag is used, allows context-dependent attackers to cause a denial of service (invalid free) and possibly execute arbitrary code via unspecified vectors, as demonstrated by an internationalized domain name to ping6.

An invalid free flaw was found in glibc's getaddrinfo() function when used with the AI_IDN flag. A remote attacker able to make an application call this function could use this flaw to execute arbitrary code with the permissions of the user running the application. Note that this flaw only affected applications using glibc compiled with libidn support.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7glibcNot affected
Red Hat Enterprise Linux 5glibcFixedRHSA-2015:162717.08.2015
Red Hat Enterprise Linux 6glibcFixedRHSA-2014:139113.10.2014

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1186614glibc: Invalid-free when using getaddrinfo()

5.1 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 11 лет назад

The getaddrinfo function in glibc before 2.15, when compiled with libidn and the AI_IDN flag is used, allows context-dependent attackers to cause a denial of service (invalid free) and possibly execute arbitrary code via unspecified vectors, as demonstrated by an internationalized domain name to ping6.

nvd
почти 11 лет назад

The getaddrinfo function in glibc before 2.15, when compiled with libidn and the AI_IDN flag is used, allows context-dependent attackers to cause a denial of service (invalid free) and possibly execute arbitrary code via unspecified vectors, as demonstrated by an internationalized domain name to ping6.

debian
почти 11 лет назад

The getaddrinfo function in glibc before 2.15, when compiled with libi ...

github
около 4 лет назад

The getaddrinfo function in glibc before 2.15, when compiled with libidn and the AI_IDN flag is used, allows context-dependent attackers to cause a denial of service (invalid free) and possibly execute arbitrary code via unspecified vectors, as demonstrated by an internationalized domain name to ping6.

oracle-oval
почти 11 лет назад

ELSA-2015-1627: glibc security update (MODERATE)

5.1 Medium

CVSS2