CVE-2012-0806
published 2012-01-27CVE-2012-0806: Buffer overflow in Bip 0.8.8 and earlier might allow remote authenticated users to execute arbitrary code via vectors involving a series of TCP connections…
PriorityP433medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
3.33%
87.4th percentile
Buffer overflow in Bip 0.8.8 and earlier might allow remote authenticated users to execute arbitrary code via vectors involving a series of TCP connections that triggers use of many open file descriptors.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bip | < bip 0.8.8-2 (bookworm) | bip 0.8.8-2 (bookworm) |
| duckcorp | bip | <= 0.8.8 | — |
| duckcorp | bip | — | — |
| duckcorp | bip | — | — |
| duckcorp | bip | — | — |
| duckcorp | bip | — | — |
| duckcorp | bip | — | — |
| duckcorp | bip | — | — |
| duckcorp | bip | — | — |
| duckcorp | bip | — | — |
| duckcorp | bip | — | — |
| duckcorp | bip | — | — |
| duckcorp | bip | — | — |
| duckcorp | bip | — | — |
| duckcorp | bip | — | — |
| duckcorp | bip | — | — |
| duckcorp | bip | >= 0 < 0.8.8-2 | 0.8.8-2 |
| duckcorp | bip | >= 0 < 0.8.8-2 | 0.8.8-2 |
| duckcorp | bip | >= 0 < 0.8.8-2 | 0.8.8-2 |
| duckcorp | bip | >= 0 < 0.8.8-2 | 0.8.8-2 |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2012-0806: bip - Buffer overflow in Bip 0.8.8 and earlier might allow remote authenticated users ...
vendor_debian·2012·CVSS 6.5
CVE-2012-0806 [MEDIUM] CVE-2012-0806: bip - Buffer overflow in Bip 0.8.8 and earlier might allow remote authenticated users ...
Buffer overflow in Bip 0.8.8 and earlier might allow remote authenticated users to execute arbitrary code via vectors involving a series of TCP connections that triggers use of many open file descriptors.
Scope: local
bookworm: resolved (fixed in 0.8.8-2)
bullseye: resolved (fixed in 0.8.8-2)
forky: resolved (fixed in 0.8.8-2)
sid: resolved (fixed in 0.8.8-2)
trixie: resolved (fixed in 0.8.8-2)
GHSA
GHSA-pw5x-fxvq-fjq4: Buffer overflow in Bip 0
ghsa_unreviewed·2022-05-17
CVE-2012-0806 [MEDIUM] CWE-119 GHSA-pw5x-fxvq-fjq4: Buffer overflow in Bip 0
Buffer overflow in Bip 0.8.8 and earlier might allow remote authenticated users to execute arbitrary code via vectors involving a series of TCP connections that triggers use of many open file descriptors.
OSV
CVE-2012-0806: Buffer overflow in Bip 0
osv·2012-01-27·CVSS 6.5
CVE-2012-0806 [MEDIUM] CVE-2012-0806: Buffer overflow in Bip 0
Buffer overflow in Bip 0.8.8 and earlier might allow remote authenticated users to execute arbitrary code via vectors involving a series of TCP connections that triggers use of many open file descriptors.
No detection rules found.
No public exploits indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=657217http://lists.fedoraproject.org/pipermail/package-announce/2012-February/072752.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-February/072767.htmlhttp://openwall.com/lists/oss-security/2012/01/24/10http://openwall.com/lists/oss-security/2012/01/24/4http://secunia.com/advisories/47679http://www.mandriva.com/security/advisories?name=MDVSA-2013:063https://projects.duckcorp.org/issues/269https://projects.duckcorp.org/projects/bip/repository/revisions/222a33cb84a2e52ad55a88900b7895bf9dd0262chttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=657217http://lists.fedoraproject.org/pipermail/package-announce/2012-February/072752.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-February/072767.htmlhttp://openwall.com/lists/oss-security/2012/01/24/10http://openwall.com/lists/oss-security/2012/01/24/4http://secunia.com/advisories/47679http://www.mandriva.com/security/advisories?name=MDVSA-2013:063https://projects.duckcorp.org/issues/269https://projects.duckcorp.org/projects/bip/repository/revisions/222a33cb84a2e52ad55a88900b7895bf9dd0262c
2012-01-27
Published