CVE-2013-4458
published 2013-12-12CVE-2013-4458: Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in GNU C Library (aka glibc or libc6) 2.18 and earlier allows remote…
PriorityP427medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
4.15%
89.8th percentile
Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in GNU C Library (aka glibc or libc6) 2.18 and earlier allows remote attackers to cause a denial of service (crash) via a (1) hostname or (2) IP address that triggers a large number of AF_INET6 address results. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-1914.
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.22-8 (bookworm) | glibc 2.22-8 (bookworm) |
| debian | glibc | < glibc 2.18-1 (bookworm) | glibc 2.18-1 (bookworm) |
| eglibc | eglibc | >= 0 < 2.19-0ubuntu6.1 | 2.19-0ubuntu6.1 |
| gnu | glibc | < 2.23 | 2.23 |
| gnu | glibc | <= 2.18 | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jcwq-q9mq-r3fv: Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo
ghsa_unreviewed·2022-05-17·CVSS 5.0
CVE-2013-4458 [MEDIUM] CWE-119 GHSA-jcwq-q9mq-r3fv: Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo
Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in GNU C Library (aka glibc or libc6) 2.18 and earlier allows remote attackers to cause a denial of service (crash) via a (1) hostname or (2) IP address that triggers a large number of AF_INET6 address results. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-1914.
GHSA
GHSA-2x2r-j2qj-78q7: Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo
ghsa_unreviewed·2022-05-13·CVSS 5.0
CVE-2016-3706 [MEDIUM] CWE-20 GHSA-2x2r-j2qj-78q7: Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo
Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in the GNU C Library (aka glibc or libc6) allows remote attackers to cause a denial of service (crash) via vectors involving hostent conversion. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4458.
OSV
CVE-2016-3706: Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo
osv·2016-06-10·CVSS 5.0
CVE-2016-3706 [MEDIUM] CVE-2016-3706: Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo
Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in the GNU C Library (aka glibc or libc6) allows remote attackers to cause a denial of service (crash) via vectors involving hostent conversion. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4458.
OSV
eglibc vulnerabilities
osv·2014-08-04·CVSS 7.5
CVE-2013-4357 [HIGH] eglibc vulnerabilities
eglibc vulnerabilities
Maksymilian Arciemowicz discovered that the GNU C Library incorrectly
handled the getaddrinfo() function. An attacker could use this issue to
cause a denial of service. This issue only affected Ubuntu 10.04 LTS.
(CVE-2013-4357)
It was discovered that the GNU C Library incorrectly handled the
getaddrinfo() function. An attacker could use this issue to cause a denial
of service. This issue only affected Ubuntu 10.04 LTS and Ubuntu 12.04 LTS.
(CVE-2013-4458)
Stephane Chazelas discovered that the GNU C Library incorrectly handled
locale environment variables. An attacker could use this issue to possibly
bypass certain restrictions such as the ForceCommand restrictions in
OpenSSH. (CVE-2014-0475)
David Reid, Glyph Lefkowitz, and Alex Gaynor discovered that the GNU C
L
OSV
CVE-2013-4458: Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo
osv·2013-12-12·CVSS 5.0
CVE-2013-4458 [MEDIUM] CVE-2013-4458: Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo
Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in GNU C Library (aka glibc or libc6) 2.18 and earlier allows remote attackers to cause a denial of service (crash) via a (1) hostname or (2) IP address that triggers a large number of AF_INET6 address results. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-1914.
Red Hat
glibc: stack (frame) overflow in getaddrinfo() when called with AF_INET, AF_INET6 (incomplete fix for CVE-2013-4458)
vendor_redhat·2016-04-27·CVSS 5.0
CVE-2016-3706 [MEDIUM] CWE-121 glibc: stack (frame) overflow in getaddrinfo() when called with AF_INET, AF_INET6 (incomplete fix for CVE-2013-4458)
glibc: stack (frame) overflow in getaddrinfo() when called with AF_INET, AF_INET6 (incomplete fix for CVE-2013-4458)
Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in the GNU C Library (aka glibc or libc6) allows remote attackers to cause a denial of service (crash) via vectors involving hostent conversion. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4458.
Package: compat-glibc (Red Hat Enterprise Linux 5) - Not affected
Package: glibc (Red Hat Enterprise Linux 5) - Will not fix
Package: compat-glibc (Red Hat Enterprise Linux 6) - Not affected
Package: glibc (Red Hat Enterprise Linux 6) - Will not fix
Package: compat-glibc (Red Hat Enterprise Linux 7) - Not affected
Package: glibc (Red Hat Enterprise Linux 7) - No
Debian
CVE-2016-3706: glibc - Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddr...
vendor_debian·2016·CVSS 5.0
CVE-2016-3706 [MEDIUM] CVE-2016-3706: glibc - Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddr...
Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in the GNU C Library (aka glibc or libc6) allows remote attackers to cause a denial of service (crash) via vectors involving hostent conversion. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4458.
Scope: local
bookworm: resolved (fixed in 2.22-8)
bullseye: resolved (fixed in 2.22-8)
forky: resolved (fixed in 2.22-8)
sid: resolved (fixed in 2.22-8)
trixie: resolved (fixed in 2.22-8)
Ubuntu
GNU C Library regression
vendor_ubuntu·2014-09-08·CVSS 7.5
CVE-2013-4357 [HIGH] GNU C Library regression
Title: GNU C Library regression
Summary: USN-2306-1 introduced a regression in the GNU C Library.
USN-2306-1 fixed vulnerabilities in the GNU C Library. On Ubuntu 10.04 LTS,
the fix for CVE-2013-4357 introduced a memory leak in getaddrinfo. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Maksymilian Arciemowicz discovered that the GNU C Library incorrectly
handled the getaddrinfo() function. An attacker could use this issue to
cause a denial of service. This issue only affected Ubuntu 10.04 LTS.
(CVE-2013-4357)
It was discovered that the GNU C Library incorrectly handled the
getaddrinfo() function. An attacker could use this issue to cause a denial
of service. This issue only affected Ubuntu 10.04 LTS and Ubuntu 12.04 LTS.
(CVE-2013-4458)
Ubuntu
GNU C Library regression
vendor_ubuntu·2014-08-05·CVSS 7.5
[HIGH] GNU C Library regression
Title: GNU C Library regression
Summary: USN-2306-1 introduced a regression in the GNU C Library.
USN-2306-1 fixed vulnerabilities in the GNU C Library. On Ubuntu 10.04 LTS,
the security update cause a regression in certain environments that use
the Name Service Caching Daemon (nscd), such as those configured for LDAP
or MySQL authentication. In these environments, the nscd daemon may need
to be stopped manually for name resolution to resume working so that
updates can be downloaded, including environments configured for unattended
updates.
We apologize for the inconvenience.
Original advisory details:
Maksymilian Arciemowicz discovered that the GNU C Library incorrectly
handled the getaddrinfo() function. An attacker could use this issue to
cause a denial of service. This issue only
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2014-08-04·CVSS 7.5
CVE-2013-4357 [HIGH] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in the GNU C Library.
Maksymilian Arciemowicz discovered that the GNU C Library incorrectly
handled the getaddrinfo() function. An attacker could use this issue to
cause a denial of service. This issue only affected Ubuntu 10.04 LTS.
(CVE-2013-4357)
It was discovered that the GNU C Library incorrectly handled the
getaddrinfo() function. An attacker could use this issue to cause a denial
of service. This issue only affected Ubuntu 10.04 LTS and Ubuntu 12.04 LTS.
(CVE-2013-4458)
Stephane Chazelas discovered that the GNU C Library incorrectly handled
locale environment variables. An attacker could use this issue to possibly
bypass certain restrictions such as the ForceCommand restrictions in
OpenSSH. (CVE-201
Red Hat
glibc: Stack (frame) overflow in getaddrinfo() when called with AF_INET6
vendor_redhat·2013-10-22·CVSS 5.0
CVE-2013-4458 [MEDIUM] CWE-121 glibc: Stack (frame) overflow in getaddrinfo() when called with AF_INET6
glibc: Stack (frame) overflow in getaddrinfo() when called with AF_INET6
Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in GNU C Library (aka glibc or libc6) 2.18 and earlier allows remote attackers to cause a denial of service (crash) via a (1) hostname or (2) IP address that triggers a large number of AF_INET6 address results. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-1914.
It was found that getaddrinfo() did not limit the amount of stack memory used during name resolution. An attacker able to make an application resolve an attacker-controlled hostname or IP address could possibly cause the application to exhaust all stack memory and crash.
Statement: This issue affects the versions of glibc as shipped with Red Ha
Debian
CVE-2013-4458: glibc - Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddr...
vendor_debian·2013·CVSS 5.0
CVE-2013-4458 [MEDIUM] CVE-2013-4458: glibc - Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddr...
Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in GNU C Library (aka glibc or libc6) 2.18 and earlier allows remote attackers to cause a denial of service (crash) via a (1) hostname or (2) IP address that triggers a large number of AF_INET6 address results. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-1914.
Scope: local
bookworm: resolved (fixed in 2.18-1)
bullseye: resolved (fixed in 2.18-1)
forky: resolved (fixed in 2.18-1)
sid: resolved (fixed in 2.18-1)
trixie: resolved (fixed in 2.18-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-3706 glibc: stack (frame) overflow in getaddrinfo() when called with AF_INET, AF_INET6 (incomplete fix for CVE-2013-4458)
bugzilla·2016-04-27·CVSS 5.0
CVE-2016-3706 [MEDIUM] CVE-2016-3706 glibc: stack (frame) overflow in getaddrinfo() when called with AF_INET, AF_INET6 (incomplete fix for CVE-2013-4458)
CVE-2016-3706 glibc: stack (frame) overflow in getaddrinfo() when called with AF_INET, AF_INET6 (incomplete fix for CVE-2013-4458)
It was found that the fix for CVE-2013-4458 is incomplete.
A stack (frame) overflow flaw, which could led to a denial of service (application crash), was found in the way glibc's getaddrinfo() function processed certain requests when called with AF_INET or AF_INET6.
This is less substantial than the CVE-2013-4458 issue because there is an other, unfixed bug in nss_files which causes it to use gigabytes of stack space with "multi on" (our default) in /etc/host.conf. Only about 4096 addresses fit into a DNS reply, so this is not really exploitable via nss_dns (only in fringe cases with extremely small stacks, as sometimes seen with Java VMs).
Discussion:
Ack
Bugzilla
CVE-2016-3706 glibc: stack (frame) overflow in getaddrinfo() when called with AF_INET, AF_INET6 (incomplete fix for CVE-2013-4458) [fedora-all]
bugzilla·2016-04-27·CVSS 5.0
CVE-2016-3706 [MEDIUM] CVE-2016-3706 glibc: stack (frame) overflow in getaddrinfo() when called with AF_INET, AF_INET6 (incomplete fix for CVE-2013-4458) [fedora-all]
CVE-2016-3706 glibc: stack (frame) overflow in getaddrinfo() when called with AF_INET, AF_INET6 (incomplete fix for CVE-2013-4458) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit
Bugzilla
CVE-2013-4458 glibc: Stack (frame) overflow in getaddrinfo() when called with AF_INET6
bugzilla·2013-10-22·CVSS 5.0
CVE-2013-4458 [MEDIUM] CVE-2013-4458 glibc: Stack (frame) overflow in getaddrinfo() when called with AF_INET6
CVE-2013-4458 glibc: Stack (frame) overflow in getaddrinfo() when called with AF_INET6
A stack (frame) overflow flaw, which led to a denial of service (application crash), was found in the way glibc's getaddrinfo() function processed certain requests when called with AF_INET6. A similar flaw to CVE-2013-1914, this affects AF_INET6 rather than AF_UNSPEC.
A proposed patch has been submitted for review [1]. No CVE has been assigned yet.
[1] https://sourceware.org/ml/libc-alpha/2013-10/msg00733.html
Discussion:
Upstream bug report:
https://sourceware.org/bugzilla/show_bug.cgi?id=16072
---
Fix pulled into Fedora rawhide (2.18.90-13).
---
Statement:
This issue affects the versions of glibc as shipped with Red Hat Enterprise Linux 5. This issue is not planned to be fixed in Red Hat Ent
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00036.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2013:283http://www.mandriva.com/security/advisories?name=MDVSA-2013:284https://security.gentoo.org/glsa/201503-04https://sourceware.org/bugzilla/show_bug.cgi?id=16072https://sourceware.org/ml/libc-alpha/2013-10/msg00733.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00036.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2013:283http://www.mandriva.com/security/advisories?name=MDVSA-2013:284https://security.gentoo.org/glsa/201503-04https://sourceware.org/bugzilla/show_bug.cgi?id=16072https://sourceware.org/ml/libc-alpha/2013-10/msg00733.html
2013-12-12
Published