CVE-2013-4412: Null Pointer Dereference
Published Nov 4, 2019
·Updated
slim has NULL pointer dereference when using crypt() method from glibc 2.17
Affected Software
7 affected componentsFixes available
All of the following
BerliOS Slim<1.3.6
GNU glibc>=2.17
Debian Debian Linux=6.0
Debian Debian Linux=7.0
All of the following
BerliOS Slim=1.3.6
GNU glibc>=2.17
debian/slim
1.3.6-5.21.3.6-5.31.4.1-21.4.1-3
Event History
Nov 4, 2019
CVE Published
via MITRE·12:44 PM
Data Sourced
via MITRE·12:44 PM
DescriptionWeakness
Feb 18, 2026
Data Sourced
via Debian·05:01 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2013-4412?
CVE-2013-4412 is a vulnerability in the 'slim' package that causes a NULL pointer dereference when using the crypt() method from glibc 2.17.
2
What is the severity of CVE-2013-4412?
CVE-2013-4412 has a severity rating of 7.5 (high).
3
What software is affected by CVE-2013-4412?
The 'slim' package versions 1.3.6-5.1, 1.3.6-5.2, and 1.3.6-5.3 are affected by CVE-2013-4412.
4
How can I fix CVE-2013-4412?
To fix CVE-2013-4412, update the 'slim' package to a version that is not vulnerable.
5
Where can I find more information about CVE-2013-4412?
You can find more information about CVE-2013-4412 on the following websites: [openwall.com](http://www.openwall.com/lists/oss-security/2013/10/09/6), [securityfocus.com](http://www.securityfocus.com/bid/62906), [access.redhat.com](https://access.redhat.com/security/cve/cve-2013-4412).