PT-2013-1305 · Gnu+2 · Glibc+3

Hector Marco

·

Publicado

2013-10-04

·

Atualizado

2017-07-01

·

CVE-2013-4788

CVSS v2.0

5.1

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions glibc versions 2.4 through 2.17 eglibc versions 2.4 through 2.17
Description The issue is related to the PTR MANGLE implementation in glibc and eglibc, which does not properly initialize a random value for pointer protection. This can be exploited by a remote attacker to control execution flow by using a buffer overflow in an application and the known zero value of the pointer guard to calculate a pointer address in memory.
Recommendations For glibc versions 2.4 through 2.17, update to a version that properly initializes the random value for the pointer guard. For eglibc versions 2.4 through 2.17, update to a version that properly initializes the random value for the pointer guard. As a temporary workaround, consider restricting the use of applications that utilize the PTR MANGLE implementation until a patch is available.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-1035
ALT-PU-2015-2084
BDU:2016-02233
CVE-2013-4788
DLA-165-1
MGASA-2013-0340
SUSE-RU-2015:0794-1
SUSE-SU-2015:0253-1
SUSE-SU-2015:0439-1
SUSE-SU-2015:0551-1

Produtos afetados

Alt Linux
Suse
Eglibc
Glibc