Lucene search

K
cve[email protected]CVE-2013-0221
HistoryNov 23, 2013 - 6:55 p.m.

CVE-2013-0221

2013-11-2318:55:04
CWE-20
web.nvd.nist.gov
43
2
cve-2013-0221
suse coreutils
gnu coreutils
denial of service
segmentation fault
buffer overflow

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.7 Medium

AI Score

Confidence

Low

0.026 Low

EPSS

Percentile

90.3%

The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string to the sort command, when using the (1) -d or (2) -M switch, which triggers a stack-based buffer overflow in the alloca function.

Affected configurations

NVD
Node
redhatenterprise_linuxMatch6.0
Node
opensuseopensuseMatch12.1
OR
opensuseopensuseMatch12.2

Social References

More

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.7 Medium

AI Score

Confidence

Low

0.026 Low

EPSS

Percentile

90.3%