CVE-2013-7423

Advisory lineage Upstream: 0 Downstream: 11
Modified
Published: 24 Feb 2015, 15:00
Last modified:06 Aug 2024, 18:09

Vulnerability Summary

Overall Risk (default)
low
21/100
CVSS Score
5 MEDIUM
v2.0 (nvd)
EPSS Score
3.15% LOW
3% probability -1.91%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

24 Feb 2015, 15:00
Published
Vulnerability first disclosed
06 Aug 2024, 18:09
Last Modified
Vulnerability information updated

Description

The send_dg function in resolv/res_send.c in GNU C Library (aka glibc or libc6) before 2.20 does not properly reuse file descriptors, which allows remote attackers to send DNS queries to unintended locations via a large number of requests that trigger a call to the getaddrinfo function.

CVSS Metrics

  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:P/A:N

EPSS Trends

Current EPSS score: 3.15% Percentile: 87%

Techniques & Countermeasures

  • CWE-17DEPRECATED: Code

    This entry has been deprecated. It was originally used for organizing the Development View (CWE-699) and some other views, but it introduced unnecessary complexity and depth to the resulting tree.

Affected Systems

  • canonicalubuntu_linux

    10.04 | 12.04 | 14.04 | 14.10

  • gnuglibc

    < 2.20

  • opensuseopensuse

    13.1 | 13.2

  • redhatenterprise_linux_server_aus

    6.5

References (11)