CVE-2013-4550

Bip <0.8.9 - Use After Free

Title source: llm
STIX 2.1

Description

Bip before 0.8.9, when running as a daemon, writes SSL handshake errors to an unexpected file descriptor that was previously associated with stderr before stderr has been closed, which allows remote attackers to write to other sockets and have an unspecified impact via a failed SSL handshake, a different vulnerability than CVE-2011-5268. NOTE: some sources originally mapped this CVE to two different types of issues; this CVE has since been SPLIT, producing CVE-2011-5268.

References (6)

Core 6
Core References
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2013-November/122274.html
Issue Tracking x_refsource_confirm
https://projects.duckcorp.org/issues/261
Various Sources x_refsource_confirm
https://projects.duckcorp.org/versions/13
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2013-November/122278.html
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/01/02/9

Scores

EPSS 0.0222
EPSS Percentile 80.8%

Details

CWE
CWE-310
Status published
Products (12)
duckcorp/bip 0.8.0 (3 CPE variants)
duckcorp/bip 0.8.1
duckcorp/bip 0.8.2
duckcorp/bip 0.8.3
duckcorp/bip 0.8.4
duckcorp/bip 0.8.5
duckcorp/bip 0.8.6
duckcorp/bip 0.8.7
duckcorp/bip < 0.8.8
fedoraproject/fedora 18
... and 2 more
Published Dec 24, 2013
Tracked Since Feb 18, 2026