CVE-2013-0242
published 2013-02-08CVE-2013-0242: Buffer overflow in the extend_buffers function in the regular expression matcher (posix/regexec.c) in glibc, possibly 2.17 and earlier, allows…
PriorityP422medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.85%
85.2th percentile
Buffer overflow in the extend_buffers function in the regular expression matcher (posix/regexec.c) in glibc, possibly 2.17 and earlier, allows context-dependent attackers to cause a denial of service (memory corruption and crash) via crafted multibyte characters.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.17-2 (bookworm) | glibc 2.17-2 (bookworm) |
| gnu | glibc | — | — |
| gnu | glibc | >= 0 < 2.17-2 | 2.17-2 |
| gnu | glibc | >= 0 < 2.17-2 | 2.17-2 |
| gnu | glibc | >= 0 < 2.17-2 | 2.17-2 |
| gnu | glibc | >= 0 < 2.17-2 | 2.17-2 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_ubuntu7.5HIGH
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f776-wjgx-67c8: Buffer overflow in the extend_buffers function in the regular expression matcher (posix/regexec
ghsa_unreviewed·2022-05-05
CVE-2013-0242 [MEDIUM] CWE-119 GHSA-f776-wjgx-67c8: Buffer overflow in the extend_buffers function in the regular expression matcher (posix/regexec
Buffer overflow in the extend_buffers function in the regular expression matcher (posix/regexec.c) in glibc, possibly 2.17 and earlier, allows context-dependent attackers to cause a denial of service (memory corruption and crash) via crafted multibyte characters.
OSV
CVE-2013-0242: Buffer overflow in the extend_buffers function in the regular expression matcher (posix/regexec
osv·2013-02-08·CVSS 5.0
CVE-2013-0242 [MEDIUM] CVE-2013-0242: Buffer overflow in the extend_buffers function in the regular expression matcher (posix/regexec
Buffer overflow in the extend_buffers function in the regular expression matcher (posix/regexec.c) in glibc, possibly 2.17 and earlier, allows context-dependent attackers to cause a denial of service (memory corruption and crash) via crafted multibyte characters.
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2013-10-21·CVSS 7.5
CVE-2012-4412 [HIGH] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in the GNU C Library.
It was discovered that the GNU C Library incorrectly handled the strcoll()
function. An attacker could use this issue to cause a denial of service, or
possibly execute arbitrary code. (CVE-2012-4412, CVE-2012-4424)
It was discovered that the GNU C Library incorrectly handled multibyte
characters in the regular expression matcher. An attacker could use this
issue to cause a denial of service. (CVE-2013-0242)
It was discovered that the GNU C Library incorrectly handled large numbers
of domain conversion results in the getaddrinfo() function. An attacker
could use this issue to cause a denial of service. (CVE-2013-1914)
It was discovered that the GNU C Library readdir_r() function incor
Red Hat
glibc: Buffer overrun (DoS) in regexp matcher by processing multibyte characters
vendor_redhat·2013-01-29·CVSS 5.0
CVE-2013-0242 [MEDIUM] glibc: Buffer overrun (DoS) in regexp matcher by processing multibyte characters
glibc: Buffer overrun (DoS) in regexp matcher by processing multibyte characters
Buffer overflow in the extend_buffers function in the regular expression matcher (posix/regexec.c) in glibc, possibly 2.17 and earlier, allows context-dependent attackers to cause a denial of service (memory corruption and crash) via crafted multibyte characters.
A flaw was found in the regular expression matching routines that process multibyte character input. If an application utilized the glibc regular expression matching mechanism, an attacker could provide specially-crafted input that, when processed, would cause the application to crash.
Debian
CVE-2013-0242: glibc - Buffer overflow in the extend_buffers function in the regular expression matcher...
vendor_debian·2013·CVSS 5.0
CVE-2013-0242 [MEDIUM] CVE-2013-0242: glibc - Buffer overflow in the extend_buffers function in the regular expression matcher...
Buffer overflow in the extend_buffers function in the regular expression matcher (posix/regexec.c) in glibc, possibly 2.17 and earlier, allows context-dependent attackers to cause a denial of service (memory corruption and crash) via crafted multibyte characters.
Scope: local
bookworm: resolved (fixed in 2.17-2)
bullseye: resolved (fixed in 2.17-2)
forky: resolved (fixed in 2.17-2)
sid: resolved (fixed in 2.17-2)
trixie: resolved (fixed in 2.17-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-0242 glibc: Buffer overrun (DoS) in regexp matcher by processing multibyte characters [f19]
bugzilla·2013-03-18·CVSS 5.0
CVE-2013-0242 [MEDIUM] CVE-2013-0242 glibc: Buffer overrun (DoS) in regexp matcher by processing multibyte characters [f19]
CVE-2013-0242 glibc: Buffer overrun (DoS) in regexp matcher by processing multibyte characters [f19]
+++ This bug was initially created as a clone of Bug #905877 +++
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed i
Bugzilla
CVE-2013-0242 glibc: Buffer overrun (DoS) in regexp matcher by processing multibyte characters [f17]
bugzilla·2013-03-18·CVSS 5.0
CVE-2013-0242 [MEDIUM] CVE-2013-0242 glibc: Buffer overrun (DoS) in regexp matcher by processing multibyte characters [f17]
CVE-2013-0242 glibc: Buffer overrun (DoS) in regexp matcher by processing multibyte characters [f17]
+++ This bug was initially created as a clone of Bug #905877 +++
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed i
Bugzilla
CVE-2013-0242 glibc: Buffer overrun (DoS) in regexp matcher by processing multibyte characters [f18]
bugzilla·2013-01-30·CVSS 5.0
CVE-2013-0242 [MEDIUM] CVE-2013-0242 glibc: Buffer overrun (DoS) in regexp matcher by processing multibyte characters [f18]
CVE-2013-0242 glibc: Buffer overrun (DoS) in regexp matcher by processing multibyte characters [f18]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Plea
Bugzilla
CVE-2013-0242 glibc: Buffer overrun (DoS) in regexp matcher by processing multibyte characters
bugzilla·2013-01-30·CVSS 5.0
CVE-2013-0242 [MEDIUM] CVE-2013-0242 glibc: Buffer overrun (DoS) in regexp matcher by processing multibyte characters
CVE-2013-0242 glibc: Buffer overrun (DoS) in regexp matcher by processing multibyte characters
A security flaw was found in the regular expression matching routine of glibc, the GNU libc libraries, processed multibyte characters input. If an application utilized the glibc's regular expression matching mechanism, an attacker could provide a specially-crafted input that, when processed would lead to that executable crash.
Upstream bug report:
[1] http://sourceware.org/bugzilla/show_bug.cgi?id=15078
Relevant patch:
[2] http://sourceware.org/ml/libc-alpha/2013-01/msg00967.html
Discussion:
This issue affects the versions of the glibc package, as shipped with Red Hat Enterprise Linux 5 and 6.
--
This issue affects the versions of the glibc package, as shipped with Fedora release of 16, 17
http://osvdb.org/89747http://rhn.redhat.com/errata/RHSA-2013-0769.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1605.htmlhttp://secunia.com/advisories/51951http://secunia.com/advisories/55113http://sourceware.org/bugzilla/show_bug.cgi?id=15078http://sourceware.org/ml/libc-alpha/2013-01/msg00967.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2013:163http://www.openwall.com/lists/oss-security/2013/01/30/5http://www.securityfocus.com/bid/57638http://www.securitytracker.com/id/1028063http://www.ubuntu.com/usn/USN-1991-1http://www.vmware.com/security/advisories/VMSA-2014-0008.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/81707https://security.gentoo.org/glsa/201503-04http://osvdb.org/89747http://rhn.redhat.com/errata/RHSA-2013-0769.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1605.htmlhttp://secunia.com/advisories/51951http://secunia.com/advisories/55113http://sourceware.org/bugzilla/show_bug.cgi?id=15078http://sourceware.org/ml/libc-alpha/2013-01/msg00967.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2013:163http://www.openwall.com/lists/oss-security/2013/01/30/5http://www.securityfocus.com/bid/57638http://www.securitytracker.com/id/1028063http://www.ubuntu.com/usn/USN-1991-1http://www.vmware.com/security/advisories/VMSA-2014-0008.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/81707https://security.gentoo.org/glsa/201503-04
2013-02-08
Published