CVE-2013-4332
published 2013-10-09CVE-2013-4332: Multiple integer overflows in malloc/malloc.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allow context-dependent attackers to cause a denial of…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
2.61%
83.7th percentile
Multiple integer overflows in malloc/malloc.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allow context-dependent attackers to cause a denial of service (heap corruption) via a large value to the (1) pvalloc, (2) valloc, (3) posix_memalign, (4) memalign, or (5) aligned_alloc functions.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.17-93 (bookworm) | glibc 2.17-93 (bookworm) |
| gnu | glibc | <= 2.18 | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_ubuntu7.5HIGH
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jjxr-f8vh-8w2w: Multiple integer overflows in malloc/malloc
ghsa_unreviewed·2022-05-17
CVE-2013-4332 [MEDIUM] GHSA-jjxr-f8vh-8w2w: Multiple integer overflows in malloc/malloc
Multiple integer overflows in malloc/malloc.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allow context-dependent attackers to cause a denial of service (heap corruption) via a large value to the (1) pvalloc, (2) valloc, (3) posix_memalign, (4) memalign, or (5) aligned_alloc functions.
OSV
CVE-2013-4332: Multiple integer overflows in malloc/malloc
osv·2013-10-09·CVSS 4.3
CVE-2013-4332 [MEDIUM] CVE-2013-4332: Multiple integer overflows in malloc/malloc
Multiple integer overflows in malloc/malloc.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allow context-dependent attackers to cause a denial of service (heap corruption) via a large value to the (1) pvalloc, (2) valloc, (3) posix_memalign, (4) memalign, or (5) aligned_alloc functions.
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2013-10-21·CVSS 7.5
CVE-2012-4412 [HIGH] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in the GNU C Library.
It was discovered that the GNU C Library incorrectly handled the strcoll()
function. An attacker could use this issue to cause a denial of service, or
possibly execute arbitrary code. (CVE-2012-4412, CVE-2012-4424)
It was discovered that the GNU C Library incorrectly handled multibyte
characters in the regular expression matcher. An attacker could use this
issue to cause a denial of service. (CVE-2013-0242)
It was discovered that the GNU C Library incorrectly handled large numbers
of domain conversion results in the getaddrinfo() function. An attacker
could use this issue to cause a denial of service. (CVE-2013-1914)
It was discovered that the GNU C Library readdir_r() function incor
Red Hat
glibc: three integer overflows in memory allocator
vendor_redhat·2013-08-20·CVSS 4.3
CVE-2013-4332 [MEDIUM] CWE-190 glibc: three integer overflows in memory allocator
glibc: three integer overflows in memory allocator
Multiple integer overflows in malloc/malloc.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allow context-dependent attackers to cause a denial of service (heap corruption) via a large value to the (1) pvalloc, (2) valloc, (3) posix_memalign, (4) memalign, or (5) aligned_alloc functions.
Multiple integer overflow flaws, leading to heap-based buffer overflows, were found in glibc's memory allocator functions (pvalloc, valloc, and memalign). If an application used such a function, it could cause the application to crash or, potentially, execute arbitrary code with the privileges of the user running the application.
Package: glibc (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-4332: glibc - Multiple integer overflows in malloc/malloc.c in the GNU C Library (aka glibc or...
vendor_debian·2013·CVSS 4.3
CVE-2013-4332 [MEDIUM] CVE-2013-4332: glibc - Multiple integer overflows in malloc/malloc.c in the GNU C Library (aka glibc or...
Multiple integer overflows in malloc/malloc.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allow context-dependent attackers to cause a denial of service (heap corruption) via a large value to the (1) pvalloc, (2) valloc, (3) posix_memalign, (4) memalign, or (5) aligned_alloc functions.
Scope: local
bookworm: resolved (fixed in 2.17-93)
bullseye: resolved (fixed in 2.17-93)
forky: resolved (fixed in 2.17-93)
sid: resolved (fixed in 2.17-93)
trixie: resolved (fixed in 2.17-93)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4332 glibc: three integer overflows in memory allocator [fedora-all]
bugzilla·2013-09-16·CVSS 4.3
CVE-2013-4332 [MEDIUM] CVE-2013-4332 glibc: three integer overflows in memory allocator [fedora-all]
CVE-2013-4332 glibc: three integer overflows in memory allocator [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue aff
Bugzilla
CVE-2013-4332 glibc: three integer overflows in memory allocator
bugzilla·2013-09-12·CVSS 4.3
CVE-2013-4332 [MEDIUM] CVE-2013-4332 glibc: three integer overflows in memory allocator
CVE-2013-4332 glibc: three integer overflows in memory allocator
Will Newton reported [1] three integer overflow flaws in the glibc memory allocator functions: pvalloc [2],[3], valloc [4],[5], and posix_memalign/memalign/assigned_alloc [6],[7]. These issues cause a large allocation size to wrap around and cause a wrong sized allocation and heap corruption.
[1] http://www.openwall.com/lists/oss-security/2013/09/11/2
[2] https://sourceware.org/bugzilla/show_bug.cgi?id=15855
[3] http://sourceware.org/git/?p=glibc.git;a=commit;h=1159a193696ad48ec86e5895f6dee3e539619c0e
[4] https://sourceware.org/bugzilla/show_bug.cgi?id=15856
[5] http://sourceware.org/git/?p=glibc.git;a=commit;h=55e17aadc1ef17a1df9626fb0e9fba290ece3331
[6] https://sourceware.org/bugzilla/show_bug.cgi?id=15857
[7] http://sou
arXiv
HuntFUZZ: Enhancing Error Handling Testing through Clustering Based Fuzzing
arxiv_fulltext·2024-07-05
HuntFUZZ: Enhancing Error Handling Testing through Clustering Based Fuzzing
frontmatter
HuntFUZZ: Enhancing Error Handling Testing through Clustering Based Fuzzing
HuntFUZZ: Enhancing Error Handling Testing through Clustering Based Fuzzing
aug
[A,B]Jin Wei [label=e1][email protected]
[B,C]Ping Chen [label=e2][email protected] author. e2.
[D]Jun Dai [label=e3]
[D]Xiaoyan Sun [label=e4]
[A]Zhihao Zhang [label=e5]
[A]Chang Xu [label=e6]
[A]Yi Wang [label=e7]
[A]School of Computer Science, Fudan University, Shanghai, China [presep=\ e1
[B]Institute of BigData, Fudan University, Shanghai, China [presep=\ e2
[C]Purple Mountain Laboratories, Nanjing, China
[D]Worcester Polytechnic Institute, Massachusetts, USA
aug
## Abstract
Testing a program's capability to effectively handling errors is a significant challenge, given that program errors are rel
http://rhn.redhat.com/errata/RHSA-2013-1411.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1605.htmlhttp://secunia.com/advisories/55113http://www.mandriva.com/security/advisories?name=MDVSA-2013:283http://www.mandriva.com/security/advisories?name=MDVSA-2013:284http://www.openwall.com/lists/oss-security/2013/09/12/6http://www.securityfocus.com/bid/62324http://www.ubuntu.com/usn/USN-1991-1https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4332https://security.gentoo.org/glsa/201503-04https://sourceware.org/bugzilla/show_bug.cgi?id=15855https://sourceware.org/bugzilla/show_bug.cgi?id=15856https://sourceware.org/bugzilla/show_bug.cgi?id=15857http://rhn.redhat.com/errata/RHSA-2013-1411.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1605.htmlhttp://secunia.com/advisories/55113http://www.mandriva.com/security/advisories?name=MDVSA-2013:283http://www.mandriva.com/security/advisories?name=MDVSA-2013:284http://www.openwall.com/lists/oss-security/2013/09/12/6http://www.securityfocus.com/bid/62324http://www.ubuntu.com/usn/USN-1991-1https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4332https://security.gentoo.org/glsa/201503-04https://sourceware.org/bugzilla/show_bug.cgi?id=15855https://sourceware.org/bugzilla/show_bug.cgi?id=15856https://sourceware.org/bugzilla/show_bug.cgi?id=15857
2013-10-09
Published