Lucene search

K
cve[email protected]CVE-2013-1950
HistoryJul 09, 2013 - 5:55 p.m.

CVE-2013-1950

2013-07-0917:55:00
CWE-399
web.nvd.nist.gov
31
cve-2013-1950
libtirpc
denial of service
remote attackers
rpcbind crash
sun rpc
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

5.2 Medium

AI Score

Confidence

High

0.171 Low

EPSS

Percentile

96.1%

The svc_dg_getargs function in libtirpc 0.2.3 and earlier allows remote attackers to cause a denial of service (rpcbind crash) via a Sun RPC request with crafted arguments that trigger a free of an invalid pointer.

Affected configurations

NVD
Node
libtirpc_projectlibtirpcRange0.2.3
OR
libtirpc_projectlibtirpcMatch0.1.8
OR
libtirpc_projectlibtirpcMatch0.1.9
OR
libtirpc_projectlibtirpcMatch0.1.10
OR
libtirpc_projectlibtirpcMatch0.1.11
OR
libtirpc_projectlibtirpcMatch0.2.0
OR
libtirpc_projectlibtirpcMatch0.2.1
OR
libtirpc_projectlibtirpcMatch0.2.2

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

5.2 Medium

AI Score

Confidence

High

0.171 Low

EPSS

Percentile

96.1%