Bug 15330 (CVE-2013-1914) - Stack overflow in getaddrinfo with many results (CVE-2013-1914)
Summary: Stack overflow in getaddrinfo with many results (CVE-2013-1914)
Status: RESOLVED FIXED
Alias: CVE-2013-1914
Product: glibc
Classification: Unclassified
Component: network (show other bugs)
Version: 2.16
: P2 normal
Target Milestone: 2.18
Assignee: Not yet assigned to anyone
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2013-04-03 12:37 UTC by Andreas Schwab
Modified: 2014-06-13 10:40 UTC (History)
1 user (show)

See Also:
Host:
Target:
Build:
Last reconfirmed:
fweimer: security+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Schwab 2013-04-03 12:37:18 UTC
If gaih_inet returns many results then the subsequent sort process can overflow the stack.
Comment 1 Andreas Schwab 2013-04-03 15:34:41 UTC
CVE-2013-1914
Comment 2 Andreas Schwab 2013-04-03 16:08:58 UTC
Fixed by 1cef1b19089528db11f221e938f60b9b048945d7