Lucene search

K
cveRedhatCVE-2013-4332
HistoryOct 09, 2013 - 10:55 p.m.

CVE-2013-4332

2013-10-0922:55:02
CWE-189
redhat
web.nvd.nist.gov
75
cve-2013-4332
glibc
libc6
integer overflow
denial of service
heap corruption
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

AI Score

7.1

Confidence

High

EPSS

0.002

Percentile

61.9%

Multiple integer overflows in malloc/malloc.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allow context-dependent attackers to cause a denial of service (heap corruption) via a large value to the (1) pvalloc, (2) valloc, (3) posix_memalign, (4) memalign, or (5) aligned_alloc functions.

Affected configurations

Nvd
Node
gnuglibcRange2.18
OR
gnuglibcMatch2.0
OR
gnuglibcMatch2.0.1
OR
gnuglibcMatch2.0.2
OR
gnuglibcMatch2.0.3
OR
gnuglibcMatch2.0.4
OR
gnuglibcMatch2.0.5
OR
gnuglibcMatch2.0.6
OR
gnuglibcMatch2.1
OR
gnuglibcMatch2.1.1
OR
gnuglibcMatch2.1.1.6
OR
gnuglibcMatch2.1.2
OR
gnuglibcMatch2.1.3
OR
gnuglibcMatch2.1.9
OR
gnuglibcMatch2.10.1
OR
gnuglibcMatch2.11
OR
gnuglibcMatch2.11.1
OR
gnuglibcMatch2.11.2
OR
gnuglibcMatch2.11.3
OR
gnuglibcMatch2.12.1
OR
gnuglibcMatch2.12.2
OR
gnuglibcMatch2.13
OR
gnuglibcMatch2.14
OR
gnuglibcMatch2.14.1
OR
gnuglibcMatch2.15
OR
gnuglibcMatch2.16
OR
gnuglibcMatch2.17
Node
redhatenterprise_linuxMatch5
VendorProductVersionCPE
gnuglibc*cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*
gnuglibc2.0cpe:2.3:a:gnu:glibc:2.0:*:*:*:*:*:*:*
gnuglibc2.0.1cpe:2.3:a:gnu:glibc:2.0.1:*:*:*:*:*:*:*
gnuglibc2.0.2cpe:2.3:a:gnu:glibc:2.0.2:*:*:*:*:*:*:*
gnuglibc2.0.3cpe:2.3:a:gnu:glibc:2.0.3:*:*:*:*:*:*:*
gnuglibc2.0.4cpe:2.3:a:gnu:glibc:2.0.4:*:*:*:*:*:*:*
gnuglibc2.0.5cpe:2.3:a:gnu:glibc:2.0.5:*:*:*:*:*:*:*
gnuglibc2.0.6cpe:2.3:a:gnu:glibc:2.0.6:*:*:*:*:*:*:*
gnuglibc2.1cpe:2.3:a:gnu:glibc:2.1:*:*:*:*:*:*:*
gnuglibc2.1.1cpe:2.3:a:gnu:glibc:2.1.1:*:*:*:*:*:*:*
Rows per page:
1-10 of 281

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

AI Score

7.1

Confidence

High

EPSS

0.002

Percentile

61.9%