CVE-2013-4357: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 3.2% chance of exploitation in the next 30 days.

The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service.

Affected products

  • Canonical Ubuntu Linux: version 10.04 only; version 12.04 only; version 14.04 only
  • Debian Debian Linux: version 6.0 only; version 7.0 only
  • Eglibc Eglibc: before 2.14 (fixed in 2.14)
  • Fedoraproject Fedora: version 18 only; version 19 only
  • Novell Suse Linux Enterprise Server: version 11.0 only

Published 2019-12-31. Last modified 2026-06-16.