CVE-2013-4237

Publication date 9 October 2013

Last updated 24 July 2024


Ubuntu priority

sysdeps/posix/readdir_r.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allows context-dependent attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a crafted (1) NTFS or (2) CIFS image.

Read the notes from the security team

Status

Package Ubuntu Release Status
eglibc 13.10 saucy
Fixed 2.17-93ubuntu2
13.04 raring
Fixed 2.17-0ubuntu5.1
12.10 quantal
Fixed 2.15-0ubuntu20.2
12.04 LTS precise
Fixed 2.15-0ubuntu10.5
10.04 LTS lucid
Fixed 2.11.1-0ubuntu7.13

Notes


jdstrand

may only affect powerpc in practice

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
eglibc

References

Related Ubuntu Security Notices (USN)

    • USN-1991-1
    • GNU C Library vulnerabilities
    • 21 October 2013

Other references