CVE-2013-7424

The getaddrinfo function in glibc before 2.15, when compiled with libidn and the AI_IDN flag is used, allows context-dependent attackers to cause a denial of service (invalid free) and possibly execute arbitrary code via unspecified vectors, as demonstrated by an internationalized domain name to ping6.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.1 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 74%
Affected Products (NVD)
VendorProductVersion
gnuglibc
𝑥
≤ 2.14.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
glibc
bookworm
2.36-9+deb12u8
fixed
bookworm (security)
2.36-9+deb12u7
fixed
bullseye
2.31-13+deb11u11
fixed
bullseye (security)
2.31-13+deb11u10
fixed
sid
2.40-3
fixed
trixie
2.40-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
eglibc
lucid
not-affected
precise
not-affected
trusty
not-affected
utopic
dne
glibc
lucid
dne
precise
dne
trusty
dne
utopic
not-affected
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
glibc
RHEL 6
0:2.12-1.149.el6
fixed
glibc-common
RHEL 6
0:2.12-1.149.el6
fixed
glibc-devel
RHEL 6
0:2.12-1.149.el6
fixed
glibc-headers
RHEL 6
0:2.12-1.149.el6
fixed
glibc-static
RHEL 6
0:2.12-1.149.el6
fixed
glibc-utils
RHEL 6
0:2.12-1.149.el6
fixed
nscd
RHEL 6
0:2.12-1.149.el6
fixed
Common Weakness Enumeration