CVE-2013-7423
published 2015-02-24CVE-2013-7423: The send_dg function in resolv/res_send.c in GNU C Library (aka glibc or libc6) before 2.20 does not properly reuse file descriptors, which allows remote…
PriorityP428medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
5.81%
92.3th percentile
The send_dg function in resolv/res_send.c in GNU C Library (aka glibc or libc6) before 2.20 does not properly reuse file descriptors, which allows remote attackers to send DNS queries to unintended locations via a large number of requests that trigger a call to the getaddrinfo function.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | glibc | < glibc 2.19-1 (bookworm) | glibc 2.19-1 (bookworm) |
| eglibc | eglibc | >= 0 < 2.19-0ubuntu6.6 | 2.19-0ubuntu6.6 |
| gnu | glibc | < 2.20 | 2.20 |
| gnu | glibc | >= 0 < 2.19-1 | 2.19-1 |
| gnu | glibc | >= 0 < 2.19-1 | 2.19-1 |
| gnu | glibc | >= 0 < 2.19-1 | 2.19-1 |
| gnu | glibc | >= 0 < 2.19-1 | 2.19-1 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_server_aus | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7q6m-8g97-jq6m: The send_dg function in resolv/res_send
ghsa_unreviewed·2022-05-13
CVE-2013-7423 [MEDIUM] GHSA-7q6m-8g97-jq6m: The send_dg function in resolv/res_send
The send_dg function in resolv/res_send.c in GNU C Library (aka glibc or libc6) before 2.20 does not properly reuse file descriptors, which allows remote attackers to send DNS queries to unintended locations via a large number of requests that trigger a call to the getaddrinfo function.
OSV
eglibc, glibc vulnerabilities
osv·2015-02-26·CVSS 5.0
CVE-2013-7423 [MEDIUM] eglibc, glibc vulnerabilities
eglibc, glibc vulnerabilities
Arnaud Le Blanc discovered that the GNU C Library incorrectly handled file
descriptors when resolving DNS queries under high load. This may cause a
denial of service in other applications, or an information leak. This issue
only affected Ubuntu 10.04 LTS, Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.
(CVE-2013-7423)
It was discovered that the GNU C Library incorrectly handled receiving a
positive answer while processing the network name when performing DNS
resolution. A remote attacker could use this issue to cause the GNU C
Library to hang, resulting in a denial of service. (CVE-2014-9402)
Joseph Myers discovered that the GNU C Library wscanf function incorrectly
handled memory. A remote attacker could possibly use this issue to cause
the GNU C Library to crash,
OSV
CVE-2013-7423: The send_dg function in resolv/res_send
osv·2015-02-24·CVSS 5.0
CVE-2013-7423 [MEDIUM] CVE-2013-7423: The send_dg function in resolv/res_send
The send_dg function in resolv/res_send.c in GNU C Library (aka glibc or libc6) before 2.20 does not properly reuse file descriptors, which allows remote attackers to send DNS queries to unintended locations via a large number of requests that trigger a call to the getaddrinfo function.
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2015-02-26·CVSS 5.0
CVE-2013-7423 [MEDIUM] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in the GNU C Library.
Arnaud Le Blanc discovered that the GNU C Library incorrectly handled file
descriptors when resolving DNS queries under high load. This may cause a
denial of service in other applications, or an information leak. This issue
only affected Ubuntu 10.04 LTS, Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.
(CVE-2013-7423)
It was discovered that the GNU C Library incorrectly handled receiving a
positive answer while processing the network name when performing DNS
resolution. A remote attacker could use this issue to cause the GNU C
Library to hang, resulting in a denial of service. (CVE-2014-9402)
Joseph Myers discovered that the GNU C Library wscanf function incorrectly
handled memory. A remote at
Red Hat
glibc: getaddrinfo() writes DNS queries to random file descriptors under high load
vendor_redhat·2013-09-12·CVSS 5.0
CVE-2013-7423 [MEDIUM] CWE-362 glibc: getaddrinfo() writes DNS queries to random file descriptors under high load
glibc: getaddrinfo() writes DNS queries to random file descriptors under high load
The send_dg function in resolv/res_send.c in GNU C Library (aka glibc or libc6) before 2.20 does not properly reuse file descriptors, which allows remote attackers to send DNS queries to unintended locations via a large number of requests that trigger a call to the getaddrinfo function.
It was discovered that, under certain circumstances, glibc's getaddrinfo() function would send DNS queries to random file descriptors. An attacker could potentially use this flaw to send DNS queries to unintended recipients, resulting in information disclosure or data loss due to the application encountering corrupted data.
Statement: This issue did not affect the versions of glibc as shipped with Red Hat Enterprise Linux
Debian
CVE-2013-7423: glibc - The send_dg function in resolv/res_send.c in GNU C Library (aka glibc or libc6) ...
vendor_debian·2013·CVSS 5.0
CVE-2013-7423 [MEDIUM] CVE-2013-7423: glibc - The send_dg function in resolv/res_send.c in GNU C Library (aka glibc or libc6) ...
The send_dg function in resolv/res_send.c in GNU C Library (aka glibc or libc6) before 2.20 does not properly reuse file descriptors, which allows remote attackers to send DNS queries to unintended locations via a large number of requests that trigger a call to the getaddrinfo function.
Scope: local
bookworm: resolved (fixed in 2.19-1)
bullseye: resolved (fixed in 2.19-1)
forky: resolved (fixed in 2.19-1)
sid: resolved (fixed in 2.19-1)
trixie: resolved (fixed in 2.19-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-7423 glibc: getaddrinfo() writes DNS queries to random file descriptors under high load
bugzilla·2015-01-29·CVSS 5.0
CVE-2013-7423 [MEDIUM] CVE-2013-7423 glibc: getaddrinfo() writes DNS queries to random file descriptors under high load
CVE-2013-7423 glibc: getaddrinfo() writes DNS queries to random file descriptors under high load
It was reported [1] that under high load, getaddrinfo() starts sending DNS queries to random file descriptors, e.g. some unrelated socket connected to a remote service.
[1]: https://sourceware.org/bugzilla/show_bug.cgi?id=15946
Discussion:
FYI, there's a rhel-6.7 bug for this already:
https://bugzilla.redhat.com/show_bug.cgi?id=1144019
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2015:0863 https://rhn.redhat.com/errata/RHSA-2015-0863.html
---
Statement:
This issue did not affect the versions of glibc as shipped with Red Hat Enterprise Linux 5 as they did not include the vulnerable code, which was introduced in later versions.
---
arXiv
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
arxiv_fulltext·2022-12-29
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
## Abstract
Currently, the development of IoT firmware heavily depends on third-party components (TPCs) to improve development efficiency. Nevertheless, TPCs are not secure, and the vulnerabilities in TPCs will influence the security of IoT firmware. Existing works pay less attention to the vulnerabilities caused by TPCs, and we still lack a comprehensive understanding of the security impact of TPC vulnerability against firmware. To fill in the knowledge gap, we design and implement , which leverages syntactical features and control-flow graph features to detect the TPCs in firmware, and then recognizes the corresponding vulnerabilities. Based on , we present the first l
http://lists.opensuse.org/opensuse-updates/2015-02/msg00089.htmlhttp://packetstormsecurity.com/files/164014/Moxa-Command-Injection-Cross-Site-Scripting-Vulnerable-Software.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0863.htmlhttp://seclists.org/fulldisclosure/2021/Sep/0http://www.openwall.com/lists/oss-security/2015/01/28/20http://www.securityfocus.com/bid/72844http://www.ubuntu.com/usn/USN-2519-1https://access.redhat.com/errata/RHSA-2016:1207https://github.com/golang/go/issues/6336https://security.gentoo.org/glsa/201602-02https://sourceware.org/bugzilla/show_bug.cgi?id=15946http://lists.opensuse.org/opensuse-updates/2015-02/msg00089.htmlhttp://packetstormsecurity.com/files/164014/Moxa-Command-Injection-Cross-Site-Scripting-Vulnerable-Software.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0863.htmlhttp://seclists.org/fulldisclosure/2021/Sep/0http://www.openwall.com/lists/oss-security/2015/01/28/20http://www.securityfocus.com/bid/72844http://www.ubuntu.com/usn/USN-2519-1https://access.redhat.com/errata/RHSA-2016:1207https://github.com/golang/go/issues/6336https://security.gentoo.org/glsa/201602-02https://sourceware.org/bugzilla/show_bug.cgi?id=15946
2015-02-24
Published