Description
Bip before 0.8.9, when running as a daemon, writes SSL handshake errors to an unexpected file descriptor that was previously associated with stderr before stderr has been closed, which allows remote attackers to write to other sockets and have an unspecified impact via a failed SSL handshake, a different vulnerability than CVE-2011-5268. NOTE: some sources originally mapped this CVE to two different types of issues; this CVE has since been SPLIT, producing CVE-2011-5268.
References (6)
Core 6
Core References
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2013-November/122274.html
Issue Tracking x_refsource_confirm
https://projects.duckcorp.org/issues/261
Various Sources x_refsource_confirm
https://projects.duckcorp.org/versions/13
Patch vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2013-November/121868.html
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2013-November/122278.html
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/01/02/9
Scores
EPSS
0.0222
EPSS Percentile
80.8%
Details
CWE
CWE-310
Status
published
Products (12)
duckcorp/bip
0.8.0 (3 CPE variants)
duckcorp/bip
0.8.1
duckcorp/bip
0.8.2
duckcorp/bip
0.8.3
duckcorp/bip
0.8.4
duckcorp/bip
0.8.5
duckcorp/bip
0.8.6
duckcorp/bip
0.8.7
duckcorp/bip
< 0.8.8
fedoraproject/fedora
18
... and 2 more
Published
Dec 24, 2013
Tracked Since
Feb 18, 2026