5
CVSSv2

CVE-2013-1914

Published: 29/04/2013 Updated: 13/02/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in GNU C Library (aka glibc or libc6) 2.17 and previous versions allows remote malicious users to cause a denial of service (crash) via a (1) hostname or (2) IP address that triggers a large number of domain conversion results.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnu glibc 2.2.2

gnu glibc 2.9

gnu glibc 2.7

gnu glibc 2.11

gnu glibc 2.2.5

gnu glibc 2.0.6

gnu glibc 2.10.1

gnu glibc 2.14

gnu glibc 2.3.1

gnu glibc 2.3

gnu glibc 2.13

gnu glibc 2.4

gnu glibc 2.3.4

gnu glibc 2.3.3

gnu glibc 2.12.1

gnu glibc 2.6.1

gnu glibc 2.0.1

gnu glibc 2.14.1

gnu glibc 2.11.2

gnu glibc 2.5.1

gnu glibc 2.6

gnu glibc 2.2.1

gnu glibc 2.3.2

gnu glibc 2.16

gnu glibc 2.3.6

gnu glibc 2.2.3

gnu glibc 2.5

gnu glibc

gnu glibc 2.11.3

gnu glibc 2.3.5

gnu glibc 2.8

gnu glibc 2.11.1

gnu glibc 2.2.4

gnu glibc 2.15

gnu glibc 2.2

gnu glibc 2.12.2

Vendor Advisories

Synopsis Low: glibc security and bug fix update Type/Severity Security Advisory: Low Topic Updated glibc packages that fix two security issues and two bugs are nowavailable for Red Hat Enterprise Linux 5The Red Hat Security Response Team has rated this update as having lowsecurity impact Common Vulnerabil ...
Synopsis Moderate: glibc security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic Updated glibc packages that fix three security issues, several bugs, andadd various enhancements are now available for Red Hat Enterprise Linux 6The Red Hat Security Response Team has rated th ...
Several security issues were fixed in the GNU C Library ...
Multiple integer overflow flaws, leading to heap-based buffer overflows, were found in glibc's memory allocator functions (pvalloc, valloc, and memalign) If an application used such a function, it could cause the application to crash or, potentially, execute arbitrary code with the privileges of the user running the application (CVE-2013-4332) A ...
Debian Bug report logs - #699399 [CVE-2013-0242] glibc: DoS due to a buffer overrun in regexp matcher by processing multibyte characters Package: eglibc; Maintainer for eglibc is (unknown); Reported by: Luciano Bello <luciano@debianorg> Date: Wed, 30 Jan 2013 23:39:02 UTC Severity: important Tags: patch, security Found i ...
Debian Bug report logs - #704623 eglibc: CVE-2013-1914: getaddrinfo() stack overflow Package: eglibc; Maintainer for eglibc is (unknown); Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 3 Apr 2013 17:45:02 UTC Severity: important Tags: patch, security, upstream Found in versions 2113-1, 213-38, 2113 ...
Debian Bug report logs - #687530 eglibc: CVE-2012-4412: strcoll integer / buffer overflow Package: eglibc; Maintainer for eglibc is (unknown); Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Thu, 13 Sep 2012 14:21:01 UTC Severity: important Tags: patch, security Found in versions eglibc/2113-4, eglibc/217-93 Fix ...
Debian Bug report logs - #689423 eglibc: CVE-2012-4424: stack overflow in strcoll() Package: eglibc; Maintainer for eglibc is (unknown); Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Tue, 2 Oct 2012 13:12:01 UTC Severity: important Tags: patch, security Found in versions eglibc/2113-4, eglibc/217-93 Fixed in ...
Debian Bug report logs - #717178 CVE-2013-4788: PTR_MANGLE ineffective for statically linked binaries Package: eglibc; Maintainer for eglibc is (unknown); Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Wed, 17 Jul 2013 14:24:01 UTC Severity: important Tags: security Found in versions eglibc/2113-4, eglibc/217-9 ...
Debian Bug report logs - #722536 eglibc: CVE-2013-4332 Package: eglibc; Maintainer for eglibc is (unknown); Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Thu, 12 Sep 2013 05:27:02 UTC Severity: grave Tags: patch, security Fixed in versions eglibc/217-93, eglibc/213-38+deb7u1 Done: Aurelien Jarno <aurel32@de ...
Debian Bug report logs - #719558 eglibc: CVE-2013-4237 Package: eglibc; Maintainer for eglibc is (unknown); Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Tue, 13 Aug 2013 05:15:02 UTC Severity: important Tags: security Found in versions eglibc/2113-4, eglibc/217-93 Fixed in versions eglibc/217-94, eglibc/213 ...
Debian Bug report logs - #727181 eglibc: CVE-2013-4458: Stack (frame) overflow in getaddrinfo() when called with AF_INET6 Package: eglibc; Maintainer for eglibc is (unknown); Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 23 Oct 2013 04:54:01 UTC Severity: important Tags: security, upstream Fixed in vers ...
It was found that getaddrinfo() did not limit the amount of stack memory used during name resolution An attacker able to make an application resolve an attacker-controlled hostname or IP address could possibly cause the application to exhaust all stack memory and crash ...

Exploits

Many Moxa devices suffer from command injection, cross site scripting, and outdated software vulnerabilities ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> SEC Consult SA-20210901-0 :: Multiple vulnerabilities in MOXA devices <!--X-Subject-Header-End--> <!--X-Head-of-Messag ...