VulnerabilityModified
CVE-2012-0806
Buffer overflow in Bip 0.8.8 and earlier might allow remote authenticated users to execute arbitrary code via vectors involving a series of TCP connections that triggers use of many open file descriptors.
MEDIUM 6.5EPSS 3.29%
Does this matter?
Lower severity and a low EPSS score (3.29%). Track it; it rarely justifies an emergency change on its own.
Description
Buffer overflow in Bip 0.8.8 and earlier might allow remote authenticated users to execute arbitrary code via vectors involving a series of TCP connections that triggers use of many open file descriptors.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 3.29% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- duckcorp/bip
- Source
- secalert@redhat.com
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=657217Patch
- http://lists.fedoraproject.org/pipermail/package-announce/2012-February/072752.html
- http://lists.fedoraproject.org/pipermail/package-announce/2012-February/072767.html
- http://openwall.com/lists/oss-security/2012/01/24/10Patch
- http://openwall.com/lists/oss-security/2012/01/24/4
- http://secunia.com/advisories/47679Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:063
- https://projects.duckcorp.org/issues/269Patch
- https://projects.duckcorp.org/projects/bip/repository/revisions/222a33cb84a2e52ad55a88900b7895bf9dd0262cPatch
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=657217Patch
- http://lists.fedoraproject.org/pipermail/package-announce/2012-February/072752.html
- http://lists.fedoraproject.org/pipermail/package-announce/2012-February/072767.html
- http://openwall.com/lists/oss-security/2012/01/24/10Patch
- http://openwall.com/lists/oss-security/2012/01/24/4
- http://secunia.com/advisories/47679Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:063
- https://projects.duckcorp.org/issues/269Patch
- https://projects.duckcorp.org/projects/bip/repository/revisions/222a33cb84a2e52ad55a88900b7895bf9dd0262cPatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.