CVE-2013-1914Improper Restriction of Operations within the Bounds of a Memory Buffer in Glibc

Severity
5.0MEDIUMNVD
EPSS
3.1%
top 13.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 29
Latest updateMay 13

Description

Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in GNU C Library (aka glibc or libc6) 2.17 and earlier allows remote attackers to cause a denial of service (crash) via a (1) hostname or (2) IP address that triggers a large number of domain conversion results.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Debiangnu/glibc< 2.17-2+3
NVDgnu/glibc2.17+35

🔴Vulnerability Details

3
GHSA
GHSA-gcw3-7j9c-37j4: Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo2022-05-13
OSV
CVE-2013-1914: Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo2013-04-29
CVEList
CVE-2013-1914: Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo2013-04-29

📋Vendor Advisories

4
Red Hat
glibc: Stack (frame) overflow in getaddrinfo() when called with AF_INET62013-10-22
Ubuntu
GNU C Library vulnerabilities2013-10-21
Red Hat
glibc: Stack (frame) overflow in getaddrinfo() when processing entry mapping to long list of address structures2013-04-03
Debian
CVE-2013-1914: glibc - Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddr...2013

💬Community

3
Bugzilla
CVE-2013-4458 glibc: Stack (frame) overflow in getaddrinfo() when called with AF_INET62013-10-22
Bugzilla
CVE-2013-1914 glibc: Stack (frame) overflow in getaddrinfo() when processing entry mapping to long list of address structures2013-04-03
Bugzilla
CVE-2013-1914 glibc: Stack (frame) overflow in getaddrinfo() when processing entry mapping to long list of address structures [fedora-all]2013-04-03
CVE-2013-1914 — GNU Glibc vulnerability | cvebase