CVE-2012-0698

TrouSerS < 0.3.10 - Denial of Service via Crafted TCP Packet

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-0698. PoCs published by Andy Lutomirski.

AI-analyzed exploit summary This exploit triggers a denial-of-service (DoS) condition in the TCSD (Trousers) daemon by sending a malformed packet to port 30003. The packet manipulates the `LoadKeyByBlob` ordinal with invalid offsets, causing a crash.

Description

tcsd in TrouSerS before 0.3.10 allows remote attackers to cause a denial of service (daemon crash) via a crafted type_offset value in a TCP packet to port 30003.

Exploits (1)

exploitdb WORKING POC
by Andy Lutomirski · pythondoslinux
https://www.exploit-db.com/exploits/22904

This exploit triggers a denial-of-service (DoS) condition in the TCSD (Trousers) daemon by sending a malformed packet to port 30003. The packet manipulates the `LoadKeyByBlob` ordinal with invalid offsets, causing a crash.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Trousers (TCSD) daemon
No auth needed
Prerequisites: Network access to the TCSD daemon on port 30003
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

EPSS 0.1051
EPSS Percentile 95.2%

Details

CWE
CWE-119
Status published
Products (14)
trustedcomputinggroup/trousers 0.2.8
trustedcomputinggroup/trousers 0.2.9
trustedcomputinggroup/trousers 0.2.9.1
trustedcomputinggroup/trousers 0.2.9.2
trustedcomputinggroup/trousers 0.3.0
trustedcomputinggroup/trousers 0.3.1
trustedcomputinggroup/trousers 0.3.2
trustedcomputinggroup/trousers 0.3.3
trustedcomputinggroup/trousers 0.3.4
trustedcomputinggroup/trousers 0.3.5
... and 4 more
Published Nov 26, 2012
Tracked Since Feb 18, 2026