PT-2013-1305 · Gnu+2 · Glibc+3

Hector Marco

·

Published

2013-10-04

·

Updated

2017-07-01

·

CVE-2013-4788

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions glibc versions 2.4 through 2.17 eglibc versions 2.4 through 2.17
Description The issue is related to the PTR MANGLE implementation in glibc and eglibc, which does not properly initialize a random value for pointer protection. This can be exploited by a remote attacker to control execution flow by using a buffer overflow in an application and the known zero value of the pointer guard to calculate a pointer address in memory.
Recommendations For glibc versions 2.4 through 2.17, update to a version that properly initializes the random value for the pointer guard. For eglibc versions 2.4 through 2.17, update to a version that properly initializes the random value for the pointer guard. As a temporary workaround, consider restricting the use of applications that utilize the PTR MANGLE implementation until a patch is available.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1035
ALT-PU-2015-2084
BDU:2016-02233
CVE-2013-4788
DLA-165-1
MGASA-2013-0340
SUSE-RU-2015:0794-1
SUSE-SU-2015:0253-1
SUSE-SU-2015:0439-1
SUSE-SU-2015:0551-1

Affected Products

Alt Linux
Suse
Eglibc
Glibc