Lucene search

K
cveCanonicalCVE-2013-1049
HistoryMar 14, 2013 - 3:13 a.m.

CVE-2013-1049

2013-03-1403:13:16
CWE-119
canonical
web.nvd.nist.gov
45
cve-2013-1049
buffer overflow
rfc1413
ident
cfingerd
denial of service
crash
arbitrary code
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

High

EPSS

0.008

Percentile

82.2%

Buffer overflow in the RFC1413 (ident) client in cfingerd 1.4.3-3 allows remote IDENT servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted response.

Affected configurations

Nvd
Node
debiancfingerdMatch1.4.3-3
VendorProductVersionCPE
debiancfingerd1.4.3-3cpe:2.3:a:debian:cfingerd:1.4.3-3:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

High

EPSS

0.008

Percentile

82.2%