[Forgot Password]
Login  Register Subscribe

23631

 
 

115038

 
 

96174

 
 

909

 
 

78077

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2013-0288

Date: (C)2013-03-06   (M)2017-08-29
 
CVSS Score: 6.8Access Vector: NETWORK
Exploitability Subscore: 8.6Access Complexity: MEDIUM
Impact Subscore: 6.4Authentication: NONE
 Confidentiality: PARTIAL
 Integrity: PARTIAL
 Availability: PARTIAL











nss-pam-ldapd before 0.7.18 and 0.8.x before 0.8.11 allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code by performing a name lookup on an application with a large number of open file descriptors, which triggers a stack-based buffer overflow related to incorrect use of the FD_SET macro.

Reference:
SECUNIA-52212
SECUNIA-52242
BID-58007
DSA-2628
FEDORA-2013-2754
MDVSA-2013:106
RHSA-2013:0590
http://lists.arthurdejong.org/nss-pam-ldapd-announce/2013/msg00001.html
http://www.openwall.com/lists/oss-security/2013/02/18/2
http://arthurdejong.org/git/nss-pam-ldapd/commit/?id=7867b93f9a7c76b96f1571cddc1de0811134bb81
http://arthurdejong.org/git/nss-pam-ldapd/commit/?id=abf03bc54032beeff95b1b8634cc005137e11f32
http://arthurdejong.org/git/nss-pam-ldapd/commit/?id=f266f05f20afe73e89c3946a7bd60bd7c5948e1b
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=690319
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-0288
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0071
nsspamldapd-fdsetsize-bo(82175)
openSUSE-SU-2013:0522
openSUSE-SU-2013:0524

CPE    52
cpe:/a:arthurdejong:nss-pam-ldapd:0.7.10
cpe:/a:arthurdejong:nss-pam-ldapd:0.7.11
cpe:/a:arthurdejong:nss-pam-ldapd:0.7.12
cpe:/a:arthurdejong:nss-pam-ldapd:0.7.13
...
CWE    1
CWE-119
OVAL    6
oval:org.secpod.oval:def:104680
oval:org.secpod.oval:def:501006
oval:org.secpod.oval:def:202587
oval:org.secpod.oval:def:600971
...

© 2013 SecPod Technologies