Severity
7.5HIGH
EPSS
1.2%
top 21.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 31
Latest updateMay 5

Description

The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

NVDeglibc/eglibc< 2.14
Ubuntueglibc< 2.19-0ubuntu6.1
CVEListV5eglibc/eglibcbefore 2.14

Also affects: Debian Linux 6.0, 7.0, Fedora 18, 19, Ubuntu Linux 10.04, 12.04, 14.04

Patches

🔴Vulnerability Details

3
GHSA
GHSA-66q2-73gm-f5mq: The eglibc package before 22022-05-05
CVEList
CVE-2013-4357: The eglibc package before 22019-12-31
OSV
eglibc vulnerabilities2014-08-04

📋Vendor Advisories

4
Ubuntu
GNU C Library regression2014-09-08
Ubuntu
GNU C Library vulnerabilities2014-08-04
Red Hat
glibc: stack overflow in getaddrinfo()'s use of alloca()2011-04-13
Red Hat
glibc: stack overflow in getaddrinfo()'s use of alloca()2011-04-13

💬Community

1
Bugzilla
CVE-2012-6686 CVE-2013-4357 glibc: stack overflow in getaddrinfo()'s use of alloca()2013-09-18