CVE-2013-2131

rrdtool 1.4.7 - Denial of Service via Format String Specifiers in rrdtool.graph

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2013-2131. PoCs published by Thomas Pollet.

AI-analyzed exploit summary This exploit targets a format-string vulnerability in the RRDtool module for Python (CVE-2013-2131). It sends maliciously crafted format strings to a network service to potentially execute arbitrary code or crash the application.

Description

Format string vulnerability in the rrdtool module 1.4.7 for Python, as used in Zenoss, allows context-dependent attackers to cause a denial of service (crash) via format string specifiers to the rrdtool.graph function.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Thomas Pollet · cremotemultiple
https://www.exploit-db.com/exploits/38521

This exploit targets a format-string vulnerability in the RRDtool module for Python (CVE-2013-2131). It sends maliciously crafted format strings to a network service to potentially execute arbitrary code or crash the application.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: RRDtool 1.4.7 (Python module)
No auth needed
Prerequisites: Network access to the target service · Target service using vulnerable RRDtool version
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2013/04/18/5
Issue Tracking x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=969296
Issue Tracking x_refsource_misc
https://github.com/oetiker/rrdtool-1.x/pull/397
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2013/05/19/5
Issue Tracking x_refsource_misc
https://github.com/oetiker/rrdtool-1.x/issues/396
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2013/05/31/2

Scores

EPSS 0.1091
EPSS Percentile 95.3%

Details

CWE
CWE-134
Status published
Products (1)
rrdtool_project/rrdtool 1.4.7
Published Jan 04, 2015
Tracked Since Feb 18, 2026