CVE-2013-4788: GNU Eglibc
Medium severity, CVSS 5.1. EPSS: 11.4% chance of exploitation in the next 30 days.
The PTR_MANGLE implementation in the GNU C Library (aka glibc or libc6) 2.4, 2.17, and earlier, and Embedded GLIBC (EGLIBC) does not initialize the random value for the pointer guard, which makes it easier for context-dependent attackers to control execution flow by leveraging a buffer-overflow vulnerability in an application and using the known zero value pointer guard to calculate a pointer address.
Affected products
- GNU Eglibc: any version
- GNU Glibc: up to and including 2.17; version 2.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.0.4 only; …
Published 2013-10-04. Last modified 2026-06-16.