Vulnerability Name:

CVE-2013-0238 (CCN-81695)

Assigned:2012-12-06
Published:2013-01-29
Updated:2017-08-29
Summary:The try_parse_v4_netmask function in hostmask.c in IRCD-Hybrid before 8.0.6 does not properly validate masks, which allows remote attackers to cause a denial of service (crash) via a mask that causes a negative number to be parsed.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
3.9 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
3.9 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-20
Vulnerability Consequences:Denial of Service
References:Source: CCN
Type: Debian Bug report logs - #699267
ircd-hybrid: CVE-2013-0238 Denial of service vulnerability in hostmask.c:try_parse_v4_netmask()

Source: CONFIRM
Type: UNKNOWN
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=699267

Source: MITRE
Type: CNA
CVE-2013-0238

Source: OSVDB
Type: UNKNOWN
89623

Source: CCN
Type: SA51948
IRCD-Hybrid "try_parse_v4_netmask()" Denial of Service Vulnerability

Source: SECUNIA
Type: Vendor Advisory
51948

Source: SECUNIA
Type: Vendor Advisory
52106

Source: CONFIRM
Type: UNKNOWN
http://svn.ircd-hybrid.org:8000/viewcvs.cgi/ircd-hybrid/trunk/src/hostmask.c?r1=1786&r2=1785&pathrev=1786

Source: DEBIAN
Type: UNKNOWN
DSA-2618

Source: DEBIAN
Type: DSA-2618
ircd-hybrid -- denial of service

Source: EXPLOIT-DB
Type: UNKNOWN
24951

Source: CCN
Type: IRCD-Hybrid Web Page
IRCD-Hybrid Project

Source: MANDRIVA
Type: UNKNOWN
MDVSA-2013:093

Source: MLIST
Type: UNKNOWN
[oss-security] 20130129 ircd-hybrid: Denial of service vulnerability in hostmask.c:try_parse_v4_netmask()

Source: BID
Type: UNKNOWN
57610

Source: CCN
Type: BID-57610
IRCD-Hybrid 'try_parse_v4_netmask()' Denial of Service Vulnerability

Source: XF
Type: UNKNOWN
ircdhybrid-tryparsev4netmask-dos(81695)

Source: XF
Type: UNKNOWN
ircdhybrid-tryparsev4netmask-dos(81695)

Source: CCN
Type: Packet Storm Security [04-12-2013]
ircd-hybrid 8.0.5 Denial Of Service

Source: CONFIRM
Type: UNKNOWN
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0055

Source: EXPLOIT-DB
Type: EXPLOIT
Offensive Security Exploit Database [04-12-2013]

Vulnerable Configuration:Configuration 1:
  • cpe:/a:ircd-hybrid:ircd-hybrid:7.2.0:*:*:*:*:*:*:*
  • OR cpe:/a:ircd-hybrid:ircd-hybrid:7.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:ircd-hybrid:ircd-hybrid:7.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:ircd-hybrid:ircd-hybrid:7.2.3:*:*:*:*:*:*:*
  • OR cpe:/a:ircd-hybrid:ircd-hybrid:7.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:ircd-hybrid:ircd-hybrid:7.3.0:rc1:*:*:*:*:*:*
  • OR cpe:/a:ircd-hybrid:ircd-hybrid:7.3.1:*:*:*:*:*:*:*
  • OR cpe:/a:ircd-hybrid:ircd-hybrid:8.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:ircd-hybrid:ircd-hybrid:8.0.0:beta1:*:*:*:*:*:*
  • OR cpe:/a:ircd-hybrid:ircd-hybrid:8.0.0:beta2:*:*:*:*:*:*
  • OR cpe:/a:ircd-hybrid:ircd-hybrid:8.0.0:beta3:*:*:*:*:*:*
  • OR cpe:/a:ircd-hybrid:ircd-hybrid:8.0.0:rc1:*:*:*:*:*:*
  • OR cpe:/a:ircd-hybrid:ircd-hybrid:8.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:ircd-hybrid:ircd-hybrid:8.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:ircd-hybrid:ircd-hybrid:8.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:ircd-hybrid:ircd-hybrid:8.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:ircd-hybrid:ircd-hybrid:*:*:*:*:*:*:*:* (Version <= 8.0.5)

  • Configuration CCN 1:
  • cpe:/a:ircd-hybrid:ircd-hybrid:8.0.5:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:20010
    P
    DSA-2618-1 ircd-hybrid - denial of service
    2014-06-23
    oval:com.ubuntu.xenial:def:201302380000000
    V
    CVE-2013-0238 on Ubuntu 16.04 LTS (xenial) - medium.
    2013-02-13
    oval:com.ubuntu.precise:def:20130238000
    V
    CVE-2013-0238 on Ubuntu 12.04 LTS (precise) - medium.
    2013-02-12
    oval:com.ubuntu.trusty:def:20130238000
    V
    CVE-2013-0238 on Ubuntu 14.04 LTS (trusty) - medium.
    2013-02-12
    oval:com.ubuntu.xenial:def:20130238000
    V
    CVE-2013-0238 on Ubuntu 16.04 LTS (xenial) - medium.
    2013-02-12
    BACK
    ircd-hybrid ircd-hybrid 7.2.0
    ircd-hybrid ircd-hybrid 7.2.1
    ircd-hybrid ircd-hybrid 7.2.2
    ircd-hybrid ircd-hybrid 7.2.3
    ircd-hybrid ircd-hybrid 7.3.0
    ircd-hybrid ircd-hybrid 7.3.0 rc1
    ircd-hybrid ircd-hybrid 7.3.1
    ircd-hybrid ircd-hybrid 8.0.0
    ircd-hybrid ircd-hybrid 8.0.0 beta1
    ircd-hybrid ircd-hybrid 8.0.0 beta2
    ircd-hybrid ircd-hybrid 8.0.0 beta3
    ircd-hybrid ircd-hybrid 8.0.0 rc1
    ircd-hybrid ircd-hybrid 8.0.1
    ircd-hybrid ircd-hybrid 8.0.2
    ircd-hybrid ircd-hybrid 8.0.3
    ircd-hybrid ircd-hybrid 8.0.4
    ircd-hybrid ircd-hybrid *
    ircd-hybrid ircd-hybrid 8.0.5