CVE-2013-7423: Canonical Ubuntu Linux

Medium severity, CVSS 5.0. EPSS: 5.8% chance of exploitation in the next 30 days.

The send_dg function in resolv/res_send.c in GNU C Library (aka glibc or libc6) before 2.20 does not properly reuse file descriptors, which allows remote attackers to send DNS queries to unintended locations via a large number of requests that trigger a call to the getaddrinfo function.

Affected products

  • Canonical Ubuntu Linux: version 10.04 only; version 12.04 only; version 14.04 only; version 14.10 only
  • GNU Glibc: before 2.20 (fixed in 2.20)
  • Opensuse Opensuse: version 13.1 only; version 13.2 only
  • Red Hat Enterprise Linux Server Aus: version 6.5 only

Published 2015-02-24. Last modified 2026-06-17.