← Back

CVE-2013-4788

nvd nist
Published: Oct 4, 2013Modified: Apr 29, 2026

JSON object

Loading...
5.1
Vector
AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploitability: 4.9 / Impact: 6.4
Source: NVD

Description

The PTR_MANGLE implementation in the GNU C Library (aka glibc or libc6) 2.4, 2.17, and earlier, and Embedded GLIBC (EGLIBC) does not initialize the random value for the pointer guard, which makes it easier for context-dependent attackers to control execution flow by leveraging a buffer-overflow vulnerability in an application and using the known zero value pointer guard to calculate a pointer address.

Affected (28)

Products: Gnu: Glibc, Eglibc
2 products
Glibc
Eglibc
Configuration A
27 vulnerable
Vulnerable SoftwareAffected Versions
Gnu
Up to 2.17
Version 2.0.1
Version 2.0.2
Version 2.0.3
Version 2.0.4
Version 2.0.5
Version 2.0.6
Version 2.0
Version 2.1.1.6
Version 2.1.1
Version 2.1.2
Version 2.1.3
Version 2.1.9
Version 2.10.1
Version 2.11.1
Version 2.11.2
Version 2.11.3
Version 2.11
Version 2.12.1
Version 2.12.2
Version 2.13
Version 2.14.1
Version 2.14
Version 2.15
Version 2.16
Version 2.1
Version 2.4
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

References (14)

Source: cve@mitre.org
ExploitPatch
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.