CVE-2013-4237
published 2013-10-09CVE-2013-4237: sysdeps/posix/readdir_r.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allows context-dependent attackers to cause a denial of service…
PriorityP433medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.83%
89.0th percentile
sysdeps/posix/readdir_r.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allows context-dependent attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a crafted (1) NTFS or (2) CIFS image.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.17-94 (bookworm) | glibc 2.17-94 (bookworm) |
| gnu | glibc | <= 2.18 | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_ubuntu7.5HIGH
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2013-10-21·CVSS 7.5
CVE-2012-4412 [HIGH] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in the GNU C Library.
It was discovered that the GNU C Library incorrectly handled the strcoll()
function. An attacker could use this issue to cause a denial of service, or
possibly execute arbitrary code. (CVE-2012-4412, CVE-2012-4424)
It was discovered that the GNU C Library incorrectly handled multibyte
characters in the regular expression matcher. An attacker could use this
issue to cause a denial of service. (CVE-2013-0242)
It was discovered that the GNU C Library incorrectly handled large numbers
of domain conversion results in the getaddrinfo() function. An attacker
could use this issue to cause a denial of service. (CVE-2013-1914)
It was discovered that the GNU C Library readdir_r() function incor
Red Hat
glibc: Buffer overwrite when using readdir_r on file systems returning file names longer than NAME_MAX characters
vendor_redhat·2013-08-11·CVSS 6.8
CVE-2013-4237 [MEDIUM] CWE-787 glibc: Buffer overwrite when using readdir_r on file systems returning file names longer than NAME_MAX characters
glibc: Buffer overwrite when using readdir_r on file systems returning file names longer than NAME_MAX characters
sysdeps/posix/readdir_r.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allows context-dependent attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a crafted (1) NTFS or (2) CIFS image.
An out-of-bounds write flaw was found in the way the glibc's readdir_r() function handled file system entries longer than the NAME_MAX character constant. A remote attacker could provide a specially crafted NTFS or CIFS file system that, when processed by an application using readdir_r(), would cause that application to crash or, potentially, allow the attacker to execute arbitrary code with the privileges of the user runn
Debian
CVE-2013-4237: glibc - sysdeps/posix/readdir_r.c in the GNU C Library (aka glibc or libc6) 2.18 and ear...
vendor_debian·2013·CVSS 6.8
CVE-2013-4237 [MEDIUM] CVE-2013-4237: glibc - sysdeps/posix/readdir_r.c in the GNU C Library (aka glibc or libc6) 2.18 and ear...
sysdeps/posix/readdir_r.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allows context-dependent attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a crafted (1) NTFS or (2) CIFS image.
Scope: local
bookworm: resolved (fixed in 2.17-94)
bullseye: resolved (fixed in 2.17-94)
forky: resolved (fixed in 2.17-94)
sid: resolved (fixed in 2.17-94)
trixie: resolved (fixed in 2.17-94)
GHSA
GHSA-2w2q-5vg5-jx48: sysdeps/posix/readdir_r
ghsa_unreviewed·2022-05-17
CVE-2013-4237 [MEDIUM] CWE-119 GHSA-2w2q-5vg5-jx48: sysdeps/posix/readdir_r
sysdeps/posix/readdir_r.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allows context-dependent attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a crafted (1) NTFS or (2) CIFS image.
OSV
CVE-2013-4237: sysdeps/posix/readdir_r
osv·2013-10-09·CVSS 6.8
CVE-2013-4237 [MEDIUM] CVE-2013-4237: sysdeps/posix/readdir_r
sysdeps/posix/readdir_r.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allows context-dependent attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a crafted (1) NTFS or (2) CIFS image.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/55113http://www.mandriva.com/security/advisories?name=MDVSA-2013:283http://www.openwall.com/lists/oss-security/2013/08/12/8http://www.securityfocus.com/bid/61729http://www.ubuntu.com/usn/USN-1991-1https://bugzilla.redhat.com/show_bug.cgi?id=995839https://security.gentoo.org/glsa/201503-04https://sourceware.org/bugzilla/show_bug.cgi?id=14699https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commitdiff%3Bh=91ce40854d0b7f865cf5024ef95a8026b76096f3http://secunia.com/advisories/55113http://www.mandriva.com/security/advisories?name=MDVSA-2013:283http://www.openwall.com/lists/oss-security/2013/08/12/8http://www.securityfocus.com/bid/61729http://www.ubuntu.com/usn/USN-1991-1https://bugzilla.redhat.com/show_bug.cgi?id=995839https://security.gentoo.org/glsa/201503-04https://sourceware.org/bugzilla/show_bug.cgi?id=14699https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commitdiff%3Bh=91ce40854d0b7f865cf5024ef95a8026b76096f3
2013-10-09
Published