CVE-2013-1886
System: pki-tps format string injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Format string vulnerability in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System 9 and 10 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in unspecified vectors, related to viewing certificates.
Vulnerabilidad de formato de cadena de texto en el sistema de procesamiento de tokens (pki-tps) en Red Hat Certificate System (RHCS) 8.1 y posiblemente Dogtag Certificate Systsem 9 y 10 permite a usuarios autenticados remotamente causar denegación de servicio (caída) y posiblemente ejecutar código arbitrario a través de especificadores de formato de cadena de texto en vectores no especificados, relacionados con la visualización de certificados.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-02-19 CVE Reserved
- 2013-05-23 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
- CWE-134: Use of Externally-Controlled Format String
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://osvdb.org/93613 | Vdb Entry | |
http://www.securityfocus.com/bid/60085 | Vdb Entry | |
http://www.securitytracker.com/id/1029685 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2013-0856.html | 2015-08-26 | |
https://bugzilla.redhat.com/show_bug.cgi?id=924870 | 2013-05-22 | |
https://access.redhat.com/security/cve/CVE-2013-1886 | 2013-05-22 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Certificate System Search vendor "Redhat" for product "Certificate System" | 8.1 Search vendor "Redhat" for product "Certificate System" and version "8.1" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Dogtag Certificate System Search vendor "Redhat" for product "Dogtag Certificate System" | 9.0 Search vendor "Redhat" for product "Dogtag Certificate System" and version "9.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Dogtag Certificate System Search vendor "Redhat" for product "Dogtag Certificate System" | 10.0 Search vendor "Redhat" for product "Dogtag Certificate System" and version "10.0" | - |
Affected
|