[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-0288Date: (C)2013-03-06   (M)2023-12-22


nss-pam-ldapd before 0.7.18 and 0.8.x before 0.8.11 allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code by performing a name lookup on an application with a large number of open file descriptors, which triggers a stack-based buffer overflow related to incorrect use of the FD_SET macro.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.8
Exploit Score: 8.6
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECUNIA-52212
SECUNIA-52242
BID-58007
DSA-2628
FEDORA-2013-2754
MDVSA-2013:106
RHSA-2013:0590
http://lists.arthurdejong.org/nss-pam-ldapd-announce/2013/msg00001.html
http://www.openwall.com/lists/oss-security/2013/02/18/2
http://arthurdejong.org/git/nss-pam-ldapd/commit/?id=7867b93f9a7c76b96f1571cddc1de0811134bb81
http://arthurdejong.org/git/nss-pam-ldapd/commit/?id=abf03bc54032beeff95b1b8634cc005137e11f32
http://arthurdejong.org/git/nss-pam-ldapd/commit/?id=f266f05f20afe73e89c3946a7bd60bd7c5948e1b
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=690319
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-0288
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0071
nsspamldapd-fdsetsize-bo(82175)
openSUSE-SU-2013:0522
openSUSE-SU-2013:0524

CWE    1
CWE-119
OVAL    7
oval:org.secpod.oval:def:104680
oval:org.secpod.oval:def:600971
oval:org.secpod.oval:def:1500035
oval:org.secpod.oval:def:601056
...

© SecPod Technologies