Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-0220
HistoryFeb 24, 2013 - 12:00 a.m.

CVE-2013-0220

2013-02-2400:00:00
ubuntu.com
ubuntu.com
17

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.049

Percentile

92.8%

The (1) sss_autofs_cmd_getautomntent and (2)
sss_autofs_cmd_getautomntbyname function in
responder/autofs/autofssrv_cmd.c and the (3) ssh_cmd_parse_request function
in responder/ssh/sshsrv_cmd.c in System Security Services Daemon (SSSD)
before 1.9.4 allow remote attackers to cause a denial of service
(out-of-bounds read, crash, and restart) via a crafted SSSD packet.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu13.04noarchsssd< 1.9.3-0ubuntu2UNKNOWN
ubuntu13.10noarchsssd< 1.9.3-0ubuntu2UNKNOWN
ubuntu14.04noarchsssd< 1.9.3-0ubuntu2UNKNOWN
ubuntu14.10noarchsssd< 1.9.3-0ubuntu2UNKNOWN
ubuntu15.04noarchsssd< 1.9.3-0ubuntu2UNKNOWN
ubuntu15.10noarchsssd< 1.9.3-0ubuntu2UNKNOWN
ubuntu16.04noarchsssd< 1.9.3-0ubuntu2UNKNOWN
ubuntu16.10noarchsssd< 1.9.3-0ubuntu2UNKNOWN
ubuntu17.04noarchsssd< 1.9.3-0ubuntu2UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.049

Percentile

92.8%