CVE-2013-4332Integer Overflow or Wraparound in Glibc

Severity
4.3MEDIUMNVD
EPSS
1.6%
top 17.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 9
Latest updateMay 17

Description

Multiple integer overflows in malloc/malloc.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allow context-dependent attackers to cause a denial of service (heap corruption) via a large value to the (1) pvalloc, (2) valloc, (3) posix_memalign, (4) memalign, or (5) aligned_alloc functions.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

Debiangnu/glibc< 2.17-93+3
NVDgnu/glibc2.18+26

Also affects: Enterprise Linux 5

Patches

🔴Vulnerability Details

3
GHSA
GHSA-jjxr-f8vh-8w2w: Multiple integer overflows in malloc/malloc2022-05-17
OSV
CVE-2013-4332: Multiple integer overflows in malloc/malloc2013-10-09
CVEList
CVE-2013-4332: Multiple integer overflows in malloc/malloc2013-10-09

📋Vendor Advisories

3
Ubuntu
GNU C Library vulnerabilities2013-10-21
Red Hat
glibc: three integer overflows in memory allocator2013-08-20
Debian
CVE-2013-4332: glibc - Multiple integer overflows in malloc/malloc.c in the GNU C Library (aka glibc or...2013

💬Community

2
Bugzilla
CVE-2013-4332 glibc: three integer overflows in memory allocator [fedora-all]2013-09-16
Bugzilla
CVE-2013-4332 glibc: three integer overflows in memory allocator2013-09-12
CVE-2013-4332 — Integer Overflow or Wraparound in Glibc | cvebase