PT-2013-1307 · Gnu+4 · Glibc+4

Will Newton

·

Publicado

2013-10-08

·

Atualizado

2024-06-15

·

CVE-2013-4332

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions glibc versions 2.18 and earlier
Description The issue is caused by multiple integer overflows in the malloc/malloc.c file of the GNU C Library, which allows context-dependent attackers to cause a denial of service, resulting in heap corruption. This can be achieved by providing a large value to the pvalloc, valloc, posix memalign, memalign, or aligned alloc functions.
Recommendations For glibc versions 2.18 and earlier, consider disabling the use of the pvalloc, valloc, posix memalign, memalign, and aligned alloc functions until a patch is available. Restrict access to these functions to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-1035
ALT-PU-2015-2084
BDU:2016-02235
BDU:2016-02236
CESA-2013_1605
CVE-2013-4332
DLA-165-1
MGASA-2013-0340
OPENSUSE-SU-2024:10154-1
RHSA-2013:1411
RHSA-2013:1605
RHSA-2013_1411
RHSA-2013_1605
SUSE-RU-2015:0794-1
SUSE-SU-2015:0253-1
SUSE-SU-2015:0439-1
SUSE-SU-2015:0551-1

Produtos afetados

Alt Linux
Centos
Red Hat
Suse
Glibc