CVE-2013-1950
rpcbind - CALLIT procedure UDP Crash (PoC)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
The svc_dg_getargs function in libtirpc 0.2.3 and earlier allows remote attackers to cause a denial of service (rpcbind crash) via a Sun RPC request with crafted arguments that trigger a free of an invalid pointer.
La función svc_dg_getargs en libtirpc v0.2.3 y anteriores permiten provocar una denegación de servicio (caída de rpcbind) a través de una petición RPC con argumentos manipulados que provocan una liberación de un puntero inválido.
These packages provide a transport-independent RPC implementation. A flaw was found in the way libtirpc decoded RPC requests. A specially-crafted RPC request could cause libtirpc to attempt to free a buffer provided by an application using the library, even when the buffer was not dynamically allocated. This could cause an application using libtirpc, such as rpcbind, to crash.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-02-19 CVE Reserved
- 2013-05-31 CVE Published
- 2013-07-16 First Exploit
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-399: Resource Management Errors
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://git.infradead.org/users/steved/libtirpc.git/commitdiff/a9f437119d79a438cb12e510f3cadd4060102c9f | X_refsource_confirm |
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/122431 | 2013-07-17 | |
https://www.exploit-db.com/exploits/26887 | 2013-07-16 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2013-0884.html | 2022-09-20 | |
https://bugzilla.redhat.com/show_bug.cgi?id=948378 | 2013-05-30 | |
https://access.redhat.com/security/cve/CVE-2013-1950 | 2013-05-30 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Libtirpc Project Search vendor "Libtirpc Project" | Libtirpc Search vendor "Libtirpc Project" for product "Libtirpc" | <= 0.2.3 Search vendor "Libtirpc Project" for product "Libtirpc" and version " <= 0.2.3" | - |
Affected
| ||||||
Libtirpc Project Search vendor "Libtirpc Project" | Libtirpc Search vendor "Libtirpc Project" for product "Libtirpc" | 0.1.8 Search vendor "Libtirpc Project" for product "Libtirpc" and version "0.1.8" | - |
Affected
| ||||||
Libtirpc Project Search vendor "Libtirpc Project" | Libtirpc Search vendor "Libtirpc Project" for product "Libtirpc" | 0.1.9 Search vendor "Libtirpc Project" for product "Libtirpc" and version "0.1.9" | - |
Affected
| ||||||
Libtirpc Project Search vendor "Libtirpc Project" | Libtirpc Search vendor "Libtirpc Project" for product "Libtirpc" | 0.1.10 Search vendor "Libtirpc Project" for product "Libtirpc" and version "0.1.10" | - |
Affected
| ||||||
Libtirpc Project Search vendor "Libtirpc Project" | Libtirpc Search vendor "Libtirpc Project" for product "Libtirpc" | 0.1.11 Search vendor "Libtirpc Project" for product "Libtirpc" and version "0.1.11" | - |
Affected
| ||||||
Libtirpc Project Search vendor "Libtirpc Project" | Libtirpc Search vendor "Libtirpc Project" for product "Libtirpc" | 0.2.0 Search vendor "Libtirpc Project" for product "Libtirpc" and version "0.2.0" | - |
Affected
| ||||||
Libtirpc Project Search vendor "Libtirpc Project" | Libtirpc Search vendor "Libtirpc Project" for product "Libtirpc" | 0.2.1 Search vendor "Libtirpc Project" for product "Libtirpc" and version "0.2.1" | - |
Affected
| ||||||
Libtirpc Project Search vendor "Libtirpc Project" | Libtirpc Search vendor "Libtirpc Project" for product "Libtirpc" | 0.2.2 Search vendor "Libtirpc Project" for product "Libtirpc" and version "0.2.2" | - |
Affected
|