PT-2013-1307 · Gnu+4 · Glibc+4

Will Newton

·

Published

2013-10-08

·

Updated

2024-06-15

·

CVE-2013-4332

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions glibc versions 2.18 and earlier
Description The issue is caused by multiple integer overflows in the malloc/malloc.c file of the GNU C Library, which allows context-dependent attackers to cause a denial of service, resulting in heap corruption. This can be achieved by providing a large value to the pvalloc, valloc, posix memalign, memalign, or aligned alloc functions.
Recommendations For glibc versions 2.18 and earlier, consider disabling the use of the pvalloc, valloc, posix memalign, memalign, and aligned alloc functions until a patch is available. Restrict access to these functions to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1035
ALT-PU-2015-2084
BDU:2016-02235
BDU:2016-02236
CESA-2013_1605
CVE-2013-4332
DLA-165-1
MGASA-2013-0340
OPENSUSE-SU-2024:10154-1
RHSA-2013:1411
RHSA-2013:1605
RHSA-2013_1411
RHSA-2013_1605
SUSE-RU-2015:0794-1
SUSE-SU-2015:0253-1
SUSE-SU-2015:0439-1
SUSE-SU-2015:0551-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Glibc