The getaddrinfo function in glibc prior to 2.15, when compiled with libidn and the AI_IDN flag is used, allows context-dependent malicious users to cause a denial of service (invalid free) and possibly execute arbitrary code via unspecified vectors, as demonstrated by an internationalized domain name to ping6.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
gnu glibc |