Vulnerability Name:

CVE-2013-4245 (CCN-174783)

Assigned:2013-08-08
Published:2013-08-08
Updated:2019-12-13
Summary:Orca has arbitrary code execution due to insecure Python module load
CVSS v3 Severity:7.3 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
6.4 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
6.9 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:4.4 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.8 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-20
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2013-4245

Source: MISC
Type: Third Party Advisory
https://access.redhat.com/security/cve/cve-2013-4245

Source: CCN
Type: Red Hat Bugzilla – Bug 995060
(CVE-2013-4245) - CVE-2013-4245 orca: Arbitrary code execution due to insecure CWD Python module load

Source: MISC
Type: Issue Tracking, Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4245

Source: MISC
Type: Issue Tracking, Third Party Advisory
https://bugzilla.suse.com/show_bug.cgi?id=CVE-2013-4245

Source: XF
Type: UNKNOWN
orca-cve20134245-code-exec(174783)

Source: CCN
Type: orca Web site
Welcome to the ORCA Forum

Source: MISC
Type: Third Party Advisory
https://security-tracker.debian.org/tracker/CVE-2013-4245

Vulnerable Configuration:Configuration 1:
  • cpe:/a:gnome:orca:-:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:debian:debian_linux:8.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20134245
    V
    CVE-2013-4245
    2022-05-20
    oval:org.opensuse.security:def:29464
    P
    Security update for chrony (Moderate)
    2021-12-22
    oval:org.opensuse.security:def:32237
    P
    Security update for glib-networking (Important)
    2021-12-13
    oval:org.opensuse.security:def:34009
    P
    Security update for mozilla-nss (Important)
    2021-12-06
    oval:org.opensuse.security:def:33058
    P
    Security update for mozilla-nss (Important)
    2021-12-06
    oval:org.opensuse.security:def:34605
    P
    Security update for webkit2gtk3 (Important)
    2021-12-01
    oval:org.opensuse.security:def:55274
    P
    Security update for java-1_7_0-openjdk (Important)
    2021-11-24
    oval:org.opensuse.security:def:30267
    P
    Security update for MozillaFirefox (Important)
    2021-11-17
    oval:org.opensuse.security:def:56089
    P
    Security update for samba (Important)
    2021-11-16
    oval:org.opensuse.security:def:30139
    P
    Security update for postgresql10 (Important)
    2021-10-20
    oval:org.opensuse.security:def:32198
    P
    Security update for webkit2gtk3 (Important)
    2021-10-06
    oval:org.opensuse.security:def:34547
    P
    Security update for the Linux Kernel (Important)
    2021-09-23
    oval:org.opensuse.security:def:29420
    P
    Security update for Mesa (Moderate)
    2021-09-16
    oval:org.opensuse.security:def:33001
    P
    Security update for qemu (Moderate)
    2021-09-09
    oval:org.opensuse.security:def:30121
    P
    Security update for openexr (Important)
    2021-09-02
    oval:org.opensuse.security:def:29403
    P
    Security update for webkit2gtk3 (Important)
    2021-08-03
    oval:org.opensuse.security:def:55925
    P
    Security update for MozillaFirefox (Important)
    2021-07-16
    oval:org.opensuse.security:def:30102
    P
    Security update for MozillaFirefox (Important)
    2021-07-16
    oval:org.opensuse.security:def:57468
    P
    Security update for ovmf (Important)
    2021-06-22
    oval:org.opensuse.security:def:56037
    P
    Security update for apache2 (Important)
    2021-06-17
    oval:org.opensuse.security:def:30210
    P
    Security update for ucode-intel (Important)
    2021-06-10
    oval:org.opensuse.security:def:36289
    P
    ruby-1.8.7.p357-0.9.17.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36247
    P
    nagios-3.0.6-1.25.36.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:33925
    P
    Security update for spice (Important)
    2021-06-08
    oval:org.opensuse.security:def:33913
    P
    Security update for curl (Moderate)
    2021-05-27
    oval:org.opensuse.security:def:29364
    P
    Security update for graphviz (Critical)
    2021-05-19
    oval:org.opensuse.security:def:32906
    P
    Security update for libnettle (Important)
    2021-04-28
    oval:org.opensuse.security:def:55889
    P
    Security update for libnettle (Important)
    2021-04-28
    oval:org.opensuse.security:def:55999
    P
    Security update for the Linux Kernel (Live Patch 36 for SLE 12 SP2) (Important)
    2021-04-12
    oval:org.opensuse.security:def:55168
    P
    Security update for spamassassin (Important)
    2021-04-12
    oval:org.opensuse.security:def:55997
    P
    Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP2) (Important)
    2021-04-12
    oval:org.opensuse.security:def:54781
    P
    Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP2) (Important)
    2021-03-17
    oval:org.opensuse.security:def:34654
    P
    Security update for apache2 (Moderate)
    2021-03-12
    oval:org.opensuse.security:def:31351
    P
    Security update for grub2 (Important)
    2021-03-02
    oval:org.opensuse.security:def:57558
    P
    Security update for perl-XML-Twig (Moderate)
    2021-03-01
    oval:org.opensuse.security:def:54759
    P
    Security update for jasper (Important)
    2021-02-16
    oval:org.opensuse.security:def:54758
    P
    Security update for wpa_supplicant (Important)
    2021-02-15
    oval:org.opensuse.security:def:28934
    P
    Security update for openvswitch (Important)
    2021-02-12
    oval:org.opensuse.security:def:54757
    P
    Security update for openvswitch (Important)
    2021-02-12
    oval:org.opensuse.security:def:55833
    P
    Security update for sudo (Important)
    2021-01-27
    oval:org.opensuse.security:def:31195
    P
    Security update for java-1_7_1-ibm (Moderate)
    2021-01-04
    oval:org.opensuse.security:def:33914
    P
    Security update for dovecot22 (Important)
    2021-01-04
    oval:org.opensuse.security:def:35231
    P
    Security update for the Linux Kernel (Important)
    2020-12-09
    oval:org.opensuse.security:def:31560
    P
    Security update for python-cryptography (Moderate)
    2020-12-04
    oval:org.opensuse.security:def:35565
    P
    hplip-3.9.8-3.4.30 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35538
    P
    e2fsprogs-1.41.9-2.1.51 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35609
    P
    libxslt-1.1.24-19.15 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:54595
    P
    libqt4-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28238
    P
    Security update for libvorbis (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27559
    P
    rubygem-i18n-0_6 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29109
    P
    Security update for java-1_6_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:31456
    P
    Security update for postgresql91
    2020-12-01
    oval:org.opensuse.security:def:56282
    P
    Security update for gstreamer-plugins-base (Low)
    2020-12-01
    oval:org.opensuse.security:def:27519
    P
    nagios on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29989
    P
    Security update for libssh2_org (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33358
    P
    Security update for openssl1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34243
    P
    Security update for postgresql94 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27986
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:34752
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:27805
    P
    Security update for libpng12-0 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30507
    P
    Security update for MozillaFirefox
    2020-12-01
    oval:org.opensuse.security:def:35400
    P
    Security update for openssh (Important)
    2020-12-01
    oval:org.opensuse.security:def:28671
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:30959
    P
    Security update for GPG2
    2020-12-01
    oval:org.opensuse.security:def:55604
    P
    Security update for ntp (Important)
    2020-12-01
    oval:org.opensuse.security:def:28770
    P
    Security update for libssh2_org
    2020-12-01
    oval:org.opensuse.security:def:54594
    P
    libpython3_4m1_0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32771
    P
    perl-libwww-perl on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35141
    P
    Security update for kernel-source (Important)
    2020-12-01
    oval:org.opensuse.security:def:28199
    P
    Security update for libgcrypt (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30713
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:27431
    P
    libapr-util1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29025
    P
    Security update for LibVNCServer (Important)
    2020-12-01
    oval:org.opensuse.security:def:31407
    P
    Security update for perl-XML-LibXML (Important)
    2020-12-01
    oval:org.opensuse.security:def:56201
    P
    Security update for qemu (Important)
    2020-12-01
    oval:org.opensuse.security:def:29915
    P
    Security update for libcgroup1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33301
    P
    xorg-x11-libs-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34145
    P
    Security update for openldap2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:27933
    P
    Security update for GraphicsMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:57394
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34751
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:27723
    P
    Security update for e2fsprogs
    2020-12-01
    oval:org.opensuse.security:def:30353
    P
    Security update for w3m
    2020-12-01
    oval:org.opensuse.security:def:33513
    P
    Security update for perl-HTML-Parser
    2020-12-01
    oval:org.opensuse.security:def:28670
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:30827
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55438
    P
    Security update for ntp (Critical)
    2020-12-01
    oval:org.opensuse.security:def:28132
    P
    Security update for jasper (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32692
    P
    kdenetwork4-filesharing on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35084
    P
    Security update for java-1_7_0-ibm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28150
    P
    Security update for jpeg (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30669
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:57632
    P
    Security update for orca (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27367
    P
    ant on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28968
    P
    Security update for openssl (Important)
    2020-12-01
    oval:org.opensuse.security:def:56163
    P
    Security update for postgresql94 (Important)
    2020-12-01
    oval:org.opensuse.security:def:29904
    P
    Security update for KVM
    2020-12-01
    oval:org.opensuse.security:def:54995
    P
    python-pyOpenSSL on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33145
    P
    libecpg6 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35499
    P
    Security update for postgresql94 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27782
    P
    Security update for krb5
    2020-12-01
    oval:org.opensuse.security:def:27595
    P
    Security update for ImageMagick
    2020-12-01
    oval:org.opensuse.security:def:33469
    P
    Security update for Kerberos
    2020-12-01
    oval:org.opensuse.security:def:30753
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55332
    P
    mutt on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28088
    P
    Security update for ghostscript-library (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31389
    P
    Security update for orca (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32681
    P
    gvim on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34983
    P
    Security update for ghostscript-library (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28097
    P
    Security update for gimp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30650
    P
    Security update for Image Magick
    2020-12-01
    oval:org.opensuse.security:def:27356
    P
    GraphicsMagick on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28882
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:34762
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:29903
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35450
    P
    Security update for perl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28296
    P
    Security update for ncurses (Important)
    2020-12-01
    oval:org.opensuse.security:def:27698
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:29315
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:31516
    P
    Security update for quagga (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34191
    P
    Security update for orca (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27531
    P
    pango-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55725
    P
    Security update for libksba (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33446
    P
    Security update for fuse
    2020-12-01
    oval:org.opensuse.security:def:28805
    P
    Security update for orca (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30742
    P
    Security update for ansible (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55159
    P
    krb5-appl-clients on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34389
    P
    Security update for transfig (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28074
    P
    Security update for freetype2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32680
    P
    gtk2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34847
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:27946
    P
    Security update for GraphicsMagick (Important)
    2020-12-01
    oval:org.opensuse.security:def:30611
    P
    Security update for squid3
    2020-12-01
    oval:org.opensuse.security:def:56118
    P
    Security update for systemd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27355
    P
    wget-openssl1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28751
    P
    Security update for libmspack
    2020-12-01
    oval:org.opensuse.security:def:31108
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:34718
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54617
    P
    libusbmuxd4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35391
    P
    Security update for openldap2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28252
    P
    Security update for libxml2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27641
    P
    Security update for libproxy
    2020-12-01
    oval:org.opensuse.security:def:29261
    P
    Security update for vim (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31495
    P
    Security update for Python
    2020-12-01
    oval:org.opensuse.security:def:34151
    P
    Security update for openssh (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27520
    P
    netatalk on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55440
    P
    Security update for dbus-1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33407
    P
    Security update for SUSE Manager Client Tools (Critical)
    2020-12-01
    oval:org.opensuse.security:def:30741
    P
    Security update for amanda (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54921
    P
    libraw9 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34300
    P
    Security update for python27 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28035
    P
    Fixing security issues on OBS toolchain (Important)
    2020-12-01
    oval:org.opensuse.security:def:34763
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:27862
    P
    Security update for Python
    2020-12-01
    oval:org.opensuse.security:def:30562
    P
    Security update for pcp
    2020-12-01
    oval:org.opensuse.security:def:35441
    P
    Security update for orca (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28682
    P
    Security update for flash-player (Critical)
    2020-12-01
    oval:org.opensuse.security:def:31051
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:34693
    P
    Security update for xorg-x11-libXext
    2020-12-01
    oval:org.opensuse.security:def:28969
    P
    Security update for orca (Moderate)
    2020-12-01
    oval:com.ubuntu.xenial:def:201342450000000
    V
    CVE-2013-4245 on Ubuntu 16.04 LTS (xenial) - low.
    2019-12-11
    oval:org.opensuse.security:def:80102
    P
    Security update for orca (Moderate)
    2015-12-02
    oval:org.opensuse.security:def:80266
    P
    Security update for orca (Moderate)
    2015-12-02
    oval:com.ubuntu.artful:def:20134245000
    V
    CVE-2013-4245 on Ubuntu 17.10 (artful) - low.
    2013-12-31
    oval:com.ubuntu.precise:def:20134245000
    V
    CVE-2013-4245 on Ubuntu 12.04 LTS (precise) - low.
    2013-12-31
    oval:com.ubuntu.trusty:def:20134245000
    V
    CVE-2013-4245 on Ubuntu 14.04 LTS (trusty) - low.
    2013-12-31
    oval:com.ubuntu.xenial:def:20134245000
    V
    CVE-2013-4245 on Ubuntu 16.04 LTS (xenial) - low.
    2013-12-31
    BACK
    gnome orca -
    debian debian linux 8.0
    debian debian linux 9.0