The getaddrinfo function in glibc before 2.15, when compiled with libidn and the AI_IDN flag is used, allows context-dependent attackers to cause a denial of service (invalid free) and possibly execute arbitrary code via unspecified vectors, as demonstrated by an internationalized domain name to ping6.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Glibc | Gnu | * | 2.14.1 (including) |
Red Hat Enterprise Linux 5 | RedHat | glibc-0:2.5-123.el5_11.3 | * |
Red Hat Enterprise Linux 6 | RedHat | glibc-0:2.12-1.149.el6 | * |