VulnerabilityModified
CVE-2013-2298
Multiple stack-based buffer overflows in the XML parser in BOINC 7.x allow attackers to have unspecified impact via a crafted XML file, related to the scheduler.
HIGH 9.3EPSS 2.58%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.58%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple stack-based buffer overflows in the XML parser in BOINC 7.x allow attackers to have unspecified impact via a crafted XML file, related to the scheduler.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 2.58% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- universityofcalifornia/boinc client
- Source
- cve@mitre.org
References
- http://boinc.berkeley.edu/gitweb/?p=boinc-v2.git%3Ba=commitdiff%3Bh=2fea03824925cbcb976f4191f4d8321e41a4d95b
- http://lists.fedoraproject.org/pipermail/package-announce/2013-December/125125.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-December/125128.html
- http://secunia.com/advisories/53192
- http://thread.gmane.org/gmane.comp.distributed.boinc.user/3741
- http://www.openwall.com/lists/oss-security/2013/04/28/3
- http://www.securityfocus.com/bid/59539
- https://exchange.xforce.ibmcloud.com/vulnerabilities/83931
- http://boinc.berkeley.edu/gitweb/?p=boinc-v2.git%3Ba=commitdiff%3Bh=2fea03824925cbcb976f4191f4d8321e41a4d95b
- http://lists.fedoraproject.org/pipermail/package-announce/2013-December/125125.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-December/125128.html
- http://secunia.com/advisories/53192
- http://thread.gmane.org/gmane.comp.distributed.boinc.user/3741
- http://www.openwall.com/lists/oss-security/2013/04/28/3
- http://www.securityfocus.com/bid/59539
- https://exchange.xforce.ibmcloud.com/vulnerabilities/83931
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.