CVE-2013-7423 describes a vulnerability in the GNU C Library (glibc) where the send_dg function in resolv/res_send.c fails to properly reuse file descriptors. This flaw allows remote attackers to redirect DNS queries to unintended locations by initiating a large volume of requests that trigger the getaddrinfo function. With a CVSS score of 5.0 (AV:N/AC:L/Au:N/C:N/I:P/A:N), this vulnerability is of medium severity, requiring no authentication and having a low attack complexity, primarily impacting the integrity of DNS resolution. There is no evidence of active exploitation, no known exploit code in Metasploit, Nuclei, or ExploitDB, and it has received negligible community discussion or media coverage, indicating a low current threat landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.5CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server_aus:6.5:*:*:*:*:*:*:* | ||
10.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:lts:*:*:* | ||
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
14.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.10:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.