hmarco.org
http://hmarco.org/bugs/CVE-2013-4788.html CVE-2013-4788
glibc and eglibc 2.5/2.7/2.13 - Local Buffer Overflow
Record summary
CVE-2013-4788 has a selected CVSS score of 5.1; EIP currently links 1 catalogued exploit.
Description
The PTR_MANGLE implementation in the GNU C Library (aka glibc or libc6) 2.4, 2.17, and earlier, and Embedded GLIBC (EGLIBC) does not initialize the random value for the pointer guard, which makes it easier for context-dependent attackers to control execution flow by leveraging a buffer-overflow vulnerability in an application and using the known zero value pointer guard to calculate a pointer address.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBglibc and eglibc 2.5/2.7/2.13 - Local Buffer OverflowExploitDB exploitby Hector Marco & Ismael RipollNot analyzed1 file
References
820150907 Glibc Pointer guarding weaknessmailing list
http://seclists.org/fulldisclosure/2015/Sep/23 MDVSA-2013:283Vendor advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2013:283 MDVSA-2013:284Vendor advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2013:284 [oss-security] 20130716 Re: CVE-2013-4788 - Eglibc PTR MANGLE bugmailing list
http://www.openwall.com/lists/oss-security/2013/07/15/9 61183vdb entry
http://www.securityfocus.com/bid/61183 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2013-4788 GLSA-201503-04Vendor advisory
https://security.gentoo.org/glsa/201503-04