Vulnerability Name:

CVE-2012-0806 (CCN-72690)

Assigned:2012-01-07
Published:2012-01-07
Updated:2013-12-13
Summary:Buffer overflow in Bip 0.8.8 and earlier might allow remote authenticated users to execute arbitrary code via vectors involving a series of TCP connections that triggers use of many open file descriptors.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:6.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P)
5.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.8 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
5.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-119
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: Bip Web Site
Bip - Bip - DuckCorp Projects

Source: CONFIRM
Type: Patch
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=657217

Source: MITRE
Type: CNA
CVE-2012-0806

Source: FEDORA
Type: UNKNOWN
FEDORA-2012-0941

Source: FEDORA
Type: UNKNOWN
FEDORA-2012-0916

Source: MLIST
Type: Patch
[oss-security] 20120124 Re: CVE request: bip buffer overflow

Source: MLIST
Type: UNKNOWN
[oss-security] 20120124 CVE request: bip buffer overflow

Source: CCN
Type: SA47679
Bip Buffer Overflow Vulnerability

Source: SECUNIA
Type: Vendor Advisory
47679

Source: DEBIAN
Type: DSA-2393
bip -- buffer overflow

Source: MANDRIVA
Type: UNKNOWN
MDVSA-2013:063

Source: CCN
Type: OSVDB ID: 78507
Bip TCP Connection File Descriptor Handling Remote Overflow

Source: CCN
Type: BID-51646
Bip File Descriptors Stack Buffer Overflow Vulnerability

Source: XF
Type: UNKNOWN
bip-fdsetsize-bo(72690)

Source: CCN
Type: Bip Bug #269
buffer overflow when number of open file descriptors >= FD_SETSIZE

Source: CONFIRM
Type: Patch
https://projects.duckcorp.org/issues/269

Source: CCN
Type: Bip Repository
Revision 222a33cb

Source: CONFIRM
Type: Patch
https://projects.duckcorp.org/projects/bip/repository/revisions/222a33cb84a2e52ad55a88900b7895bf9dd0262c

Vulnerable Configuration:Configuration 1:
  • cpe:/a:duckcorp:bip:0.7.0:*:*:*:*:*:*:*
  • OR cpe:/a:duckcorp:bip:0.7.1:*:*:*:*:*:*:*
  • OR cpe:/a:duckcorp:bip:0.7.2:*:*:*:*:*:*:*
  • OR cpe:/a:duckcorp:bip:0.7.3:*:*:*:*:*:*:*
  • OR cpe:/a:duckcorp:bip:0.7.4:*:*:*:*:*:*:*
  • OR cpe:/a:duckcorp:bip:0.7.5:*:*:*:*:*:*:*
  • OR cpe:/a:duckcorp:bip:0.8.0:*:*:*:*:*:*:*
  • OR cpe:/a:duckcorp:bip:0.8.0:rc0:*:*:*:*:*:*
  • OR cpe:/a:duckcorp:bip:0.8.0:rc1:*:*:*:*:*:*
  • OR cpe:/a:duckcorp:bip:0.8.1:*:*:*:*:*:*:*
  • OR cpe:/a:duckcorp:bip:0.8.2:*:*:*:*:*:*:*
  • OR cpe:/a:duckcorp:bip:0.8.3:*:*:*:*:*:*:*
  • OR cpe:/a:duckcorp:bip:0.8.4:*:*:*:*:*:*:*
  • OR cpe:/a:duckcorp:bip:0.8.5:*:*:*:*:*:*:*
  • OR cpe:/a:duckcorp:bip:0.8.6:*:*:*:*:*:*:*
  • OR cpe:/a:duckcorp:bip:0.8.7:*:*:*:*:*:*:*
  • OR cpe:/a:duckcorp:bip:*:*:*:*:*:*:*:* (Version <= 0.8.8)

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:15393
    P
    DSA-2393-1 bip -- buffer overflow
    2014-06-23
    oval:com.ubuntu.precise:def:20120806000
    V
    CVE-2012-0806 on Ubuntu 12.04 LTS (precise) - medium.
    2012-01-26
    BACK
    duckcorp bip 0.7.0
    duckcorp bip 0.7.1
    duckcorp bip 0.7.2
    duckcorp bip 0.7.3
    duckcorp bip 0.7.4
    duckcorp bip 0.7.5
    duckcorp bip 0.8.0
    duckcorp bip 0.8.0 rc0
    duckcorp bip 0.8.0 rc1
    duckcorp bip 0.8.1
    duckcorp bip 0.8.2
    duckcorp bip 0.8.3
    duckcorp bip 0.8.4
    duckcorp bip 0.8.5
    duckcorp bip 0.8.6
    duckcorp bip 0.8.7
    duckcorp bip *