First published: Mon Nov 04 2019(Updated: )
slim has NULL pointer dereference when using crypt() method from glibc 2.17
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Berlios Slim | =1.3.6 | |
GNU glibc | >=2.17 | |
Debian Debian Linux | =6.0 | |
Debian Debian Linux | =7.0 | |
All of | ||
Berlios Slim | <1.3.6 | |
GNU glibc | >=2.17 | |
debian/slim | 1.3.6-5.2 1.3.6-5.3 1.3.6-5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4412 is a vulnerability in the 'slim' package that causes a NULL pointer dereference when using the crypt() method from glibc 2.17.
CVE-2013-4412 has a severity rating of 7.5 (high).
The 'slim' package versions 1.3.6-5.1, 1.3.6-5.2, and 1.3.6-5.3 are affected by CVE-2013-4412.
To fix CVE-2013-4412, update the 'slim' package to a version that is not vulnerable.
You can find more information about CVE-2013-4412 on the following websites: [openwall.com](http://www.openwall.com/lists/oss-security/2013/10/09/6), [securityfocus.com](http://www.securityfocus.com/bid/62906), [access.redhat.com](https://access.redhat.com/security/cve/cve-2013-4412).