CVE-2013-7424: Medium severity GNU glibc vulnerability

Published Jan 28, 2015
·
Updated

An Invalid-free() flaw was found in the getaddrinfo() syscall of glibc. The bug only materializes if the getaddrinfo functions is called with the AIIDN flag, and if glibc has been compiled with libidn support.

This flaw was fixed in glibc-2.15 via the following commit:

https://sourceware.org/git/gitweb.cgi?p=glibc.git;a=commitdiff;h=2e96f1c7

Other sources

The getaddrinfo function in glibc before 2.15, when compiled with libidn and the AIIDN flag is used, allows context-dependent attackers to cause a denial of service (invalid free) and possibly execute arbitrary code via unspecified vectors, as demonstrated by an internationalized domain name to ping6.

Affected Software

1 affected component
GNU glibc<=2.14.1

Event History

Jan 28, 2015
Data Sourced
06:50 AM
DescriptionSeverityAffected Software
Aug 26, 2015
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2013-7424?

CVE-2013-7424 has been classified with a severity rating of medium.

2

How do I fix CVE-2013-7424?

To fix CVE-2013-7424, upgrade glibc to version 2.15 or later.

3

What systems are affected by CVE-2013-7424?

CVE-2013-7424 affects systems using glibc versions up to and including 2.14.1 with libidn support.

4

What is the nature of the vulnerability in CVE-2013-7424?

CVE-2013-7424 is an Invalid-free() flaw in the getaddrinfo() syscall.

5

Is there a workaround for CVE-2013-7424?

There are no specific workarounds for CVE-2013-7424 other than upgrading glibc.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203