Vulnerability Name: | CVE-2013-4391 (CCN-87700) | ||||||||
Assigned: | 2013-10-01 | ||||||||
Published: | 2013-10-01 | ||||||||
Updated: | 2022-01-31 | ||||||||
Summary: | Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large journal data field, which triggers a heap-based buffer overflow. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-190 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CONFIRM Type: Issue Tracking, Mailing List, Patch, Third Party Advisory http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=725357 Source: CCN Type: systemd GIT Repository Web Site systemd GIT Repository Source: CONFIRM Type: Exploit, Patch, Vendor Advisory http://cgit.freedesktop.org/systemd/systemd/commit/?id=505b6a61c22d5565e9308045c7b9bf79f7d0517e Source: MITRE Type: CNA CVE-2013-4391 Source: CCN Type: systemd Web Site systemd Source: CCN Type: oss-sec mailing list, Tue, 01 Oct 2013 10:08:21 -0600 Re: [CVE request] systemd Source: CCN Type: SA54876 systemd Weakness and Two Vulnerabilities Source: DEBIAN Type: Third Party Advisory DSA-2777 Source: DEBIAN Type: DSA-2777 systemd -- several vulnerabilities Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20131001 Re: [CVE request] systemd Source: CCN Type: BID-62739 systemd 'journald-native.c' Remote Integer Overflow Vulnerability Source: CCN Type: Red Hat Bugzilla Bug 859051 systemd: Integer overflow, leading to heap-based buffer overflow by processing native messages Source: CONFIRM Type: Issue Tracking, Patch, Third Party Advisory https://bugzilla.redhat.com/show_bug.cgi?id=859051 Source: XF Type: UNKNOWN systemd-cve20134931-journald-bo(87700) Source: GENTOO Type: Third Party Advisory GLSA-201612-34 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |