CVE-2013-4357
published 2019-12-31CVE-2013-4357: The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service.
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.23%
86.8th percentile
The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| eglibc | eglibc | < 2.14 | 2.14 |
| eglibc | eglibc | — | — |
| eglibc | eglibc | >= 0 < 2.19-0ubuntu6.1 | 2.19-0ubuntu6.1 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| novell | suse_linux_enterprise_server | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-66q2-73gm-f5mq: The eglibc package before 2
ghsa_unreviewed·2022-05-05
CVE-2013-4357 [HIGH] CWE-120 GHSA-66q2-73gm-f5mq: The eglibc package before 2
The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service.
OSV
eglibc vulnerabilities
osv·2014-08-04·CVSS 7.5
CVE-2013-4357 [HIGH] eglibc vulnerabilities
eglibc vulnerabilities
Maksymilian Arciemowicz discovered that the GNU C Library incorrectly
handled the getaddrinfo() function. An attacker could use this issue to
cause a denial of service. This issue only affected Ubuntu 10.04 LTS.
(CVE-2013-4357)
It was discovered that the GNU C Library incorrectly handled the
getaddrinfo() function. An attacker could use this issue to cause a denial
of service. This issue only affected Ubuntu 10.04 LTS and Ubuntu 12.04 LTS.
(CVE-2013-4458)
Stephane Chazelas discovered that the GNU C Library incorrectly handled
locale environment variables. An attacker could use this issue to possibly
bypass certain restrictions such as the ForceCommand restrictions in
OpenSSH. (CVE-2014-0475)
David Reid, Glyph Lefkowitz, and Alex Gaynor discovered that the GNU C
L
Ubuntu
GNU C Library regression
vendor_ubuntu·2014-09-08·CVSS 7.5
CVE-2013-4357 [HIGH] GNU C Library regression
Title: GNU C Library regression
Summary: USN-2306-1 introduced a regression in the GNU C Library.
USN-2306-1 fixed vulnerabilities in the GNU C Library. On Ubuntu 10.04 LTS,
the fix for CVE-2013-4357 introduced a memory leak in getaddrinfo. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Maksymilian Arciemowicz discovered that the GNU C Library incorrectly
handled the getaddrinfo() function. An attacker could use this issue to
cause a denial of service. This issue only affected Ubuntu 10.04 LTS.
(CVE-2013-4357)
It was discovered that the GNU C Library incorrectly handled the
getaddrinfo() function. An attacker could use this issue to cause a denial
of service. This issue only affected Ubuntu 10.04 LTS and Ubuntu 12.04 LTS.
(CVE-2013-4458)
Ubuntu
GNU C Library regression
vendor_ubuntu·2014-08-05·CVSS 7.5
[HIGH] GNU C Library regression
Title: GNU C Library regression
Summary: USN-2306-1 introduced a regression in the GNU C Library.
USN-2306-1 fixed vulnerabilities in the GNU C Library. On Ubuntu 10.04 LTS,
the security update cause a regression in certain environments that use
the Name Service Caching Daemon (nscd), such as those configured for LDAP
or MySQL authentication. In these environments, the nscd daemon may need
to be stopped manually for name resolution to resume working so that
updates can be downloaded, including environments configured for unattended
updates.
We apologize for the inconvenience.
Original advisory details:
Maksymilian Arciemowicz discovered that the GNU C Library incorrectly
handled the getaddrinfo() function. An attacker could use this issue to
cause a denial of service. This issue only
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2014-08-04·CVSS 7.5
CVE-2013-4357 [HIGH] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in the GNU C Library.
Maksymilian Arciemowicz discovered that the GNU C Library incorrectly
handled the getaddrinfo() function. An attacker could use this issue to
cause a denial of service. This issue only affected Ubuntu 10.04 LTS.
(CVE-2013-4357)
It was discovered that the GNU C Library incorrectly handled the
getaddrinfo() function. An attacker could use this issue to cause a denial
of service. This issue only affected Ubuntu 10.04 LTS and Ubuntu 12.04 LTS.
(CVE-2013-4458)
Stephane Chazelas discovered that the GNU C Library incorrectly handled
locale environment variables. An attacker could use this issue to possibly
bypass certain restrictions such as the ForceCommand restrictions in
OpenSSH. (CVE-201
Red Hat
glibc: stack overflow in getaddrinfo()'s use of alloca()
vendor_redhat·2011-04-13·CVSS 7.5
CVE-2013-4357 [HIGH] CWE-121 glibc: stack overflow in getaddrinfo()'s use of alloca()
glibc: stack overflow in getaddrinfo()'s use of alloca()
The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service.
Statement: This issue has already been addressed in Red Hat Enterprise Linux 5 via http://rhn.redhat.com/errata/RHBA-2013-0022.html and in Red Hat Enterprise Linux 6 via http://rhn.redhat.com/errata/RHBA-2012-0763.html
Package: glibc (Red Hat Enterprise Linux 5) - Not affected
Package: glibc (Red Hat Enterprise Linux 6) - Not affected
Package: glibc (Red Hat Enterprise Linux 7) - Not affected
Red Hat
glibc: stack overflow in getaddrinfo()'s use of alloca()
vendor_redhat·2011-04-13·CVSS 7.5
CVE-2012-6686 [HIGH] CWE-121 glibc: stack overflow in getaddrinfo()'s use of alloca()
glibc: stack overflow in getaddrinfo()'s use of alloca()
[REJECTED CVE] This CVE has been rejected. This candidate is a duplicate of CVE-2013-4357. Note: All CVE users should reference CVE-2013-4357 instead of this candidate.
Statement: This issue has already been addressed in Red Hat Enterprise Linux 5 via http://rhn.redhat.com/errata/RHBA-2013-0022.html and in Red Hat Enterprise Linux 6 via http://rhn.redhat.com/errata/RHBA-2012-0763.html
Package: glibc (Red Hat Enterprise Linux 7) - Not affected
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00020.htmlhttp://www.openwall.com/lists/oss-security/2013/09/17/4http://www.openwall.com/lists/oss-security/2013/09/17/8http://www.openwall.com/lists/oss-security/2015/01/28/18http://www.openwall.com/lists/oss-security/2015/01/29/21http://www.openwall.com/lists/oss-security/2015/02/24/3http://www.securityfocus.com/bid/67992http://www.ubuntu.com/usn/USN-2306-1http://www.ubuntu.com/usn/USN-2306-2http://www.ubuntu.com/usn/USN-2306-3https://access.redhat.com/security/cve/cve-2013-4357https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4357https://bugzilla.suse.com/show_bug.cgi?id=CVE-2013-4357https://exchange.xforce.ibmcloud.com/vulnerabilities/95103https://security-tracker.debian.org/tracker/CVE-2013-4357http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00020.htmlhttp://www.openwall.com/lists/oss-security/2013/09/17/4http://www.openwall.com/lists/oss-security/2013/09/17/8http://www.openwall.com/lists/oss-security/2015/01/28/18http://www.openwall.com/lists/oss-security/2015/01/29/21http://www.openwall.com/lists/oss-security/2015/02/24/3http://www.securityfocus.com/bid/67992http://www.ubuntu.com/usn/USN-2306-1http://www.ubuntu.com/usn/USN-2306-2http://www.ubuntu.com/usn/USN-2306-3https://access.redhat.com/security/cve/cve-2013-4357https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4357https://bugzilla.suse.com/show_bug.cgi?id=CVE-2013-4357https://exchange.xforce.ibmcloud.com/vulnerabilities/95103https://security-tracker.debian.org/tracker/CVE-2013-4357
2019-12-31
Published