GNU glibc 'getaddrinfo.c' Remote Code Execution Vulnerability
BID:72710
Info
GNU glibc 'getaddrinfo.c' Remote Code Execution Vulnerability
| Bugtraq ID: | 72710 |
| Class: | Design Error |
| CVE: |
CVE-2013-7424 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 27 2015 12:00AM |
| Updated: | Jul 06 2016 02:05PM |
| Credit: | Huzaifa S. Sidhpurwala |
| Vulnerable: |
Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 5 Server Oracle Enterprise Linux 5 GNU glibc 0 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 CentOS CentOS 5 |
| Not Vulnerable: | |
References
GNU glibc 'getaddrinfo.c' Remote Code Execution Vulnerability
References:
References:
- git://sourceware.org commitdiff Fix encoding for getaddrinfo (sourceware)
- glibc Homepage (GNU)
- Bug 1186614 - (CVE-2013-7424) CVE-2013-7424 glibc: Invalid-free when using getad (Bugzilla)
- IBM Advisory MIGR-5098567 (IBM)
- IBM Advisory swg21883368 (IBM)
- isg3T1022813: GNU C library (glibc) vulnerabilities affect IBM SmartCloud Entry (IBM)
- nas8N1020944 : Security Bulletin: Vulnerabilities in glibc affect Power Hardware (IBM)
- Security Bulletin: Multiple vulnerabilities in NTP, Hivex, glibc, libuser, BIND (IBM)
- swg21960485: Open Source GNU Glibc vulnerability affects IBM Security Guardium (IBM)
- swg21963297: A vulnerability in GNU glibc affects IBM Security Network Protecti (IBM)
- swg21973022: GNU C library (glibc) vulnerability affects IBM Security Access Man (IBM)