Lucene search

K
cve[email protected]CVE-2012-0806
HistoryJan 27, 2012 - 12:55 a.m.

CVE-2012-0806

2012-01-2700:55:01
CWE-119
web.nvd.nist.gov
29
cve-2012-0806
buffer overflow
bip 0.8.8
remote execution
authentication
tcp connections

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

7.3 High

AI Score

Confidence

Low

0.021 Low

EPSS

Percentile

89.3%

Buffer overflow in Bip 0.8.8 and earlier might allow remote authenticated users to execute arbitrary code via vectors involving a series of TCP connections that triggers use of many open file descriptors.

Affected configurations

NVD
Node
duckcorpbipRange0.8.8
OR
duckcorpbipMatch0.7.0
OR
duckcorpbipMatch0.7.1
OR
duckcorpbipMatch0.7.2
OR
duckcorpbipMatch0.7.3
OR
duckcorpbipMatch0.7.4
OR
duckcorpbipMatch0.7.5
OR
duckcorpbipMatch0.8.0
OR
duckcorpbipMatch0.8.0rc0
OR
duckcorpbipMatch0.8.0rc1
OR
duckcorpbipMatch0.8.1
OR
duckcorpbipMatch0.8.2
OR
duckcorpbipMatch0.8.3
OR
duckcorpbipMatch0.8.4
OR
duckcorpbipMatch0.8.5
OR
duckcorpbipMatch0.8.6
OR
duckcorpbipMatch0.8.7

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

7.3 High

AI Score

Confidence

Low

0.021 Low

EPSS

Percentile

89.3%