CVE-2013-0005
published 2013-01-09CVE-2013-0005: The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Framework 3.5, 3.5 SP1, 3.5.1, and 4, and the Management OData…
PriorityP344high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
32.10%
98.1th percentile
The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Framework 3.5, 3.5 SP1, 3.5.1, and 4, and the Management OData IIS Extension on Windows Server 2012, allows remote attackers to cause a denial of service (resource consumption and daemon restart) via crafted values in HTTP requests, aka "Replace Denial of Service Vulnerability."
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Target the WCF Replace function in the OData protocol implementation — look for crafted HTTP requests containing anomalous values passed to the Replace function that could cause resource exhaustion. ↗
- →Monitor IIS/WCF OData endpoints for abnormal resource consumption or unexpected service/daemon restarts, which are indicators of exploitation of this DoS vulnerability. ↗
- ·Vulnerability affects multiple versions of .NET Framework (3.5, 3.5 SP1, 3.5.1, 4) and the Management OData IIS Extension on Windows Server 2012; detection scope should cover all affected platforms. ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j63h-6q3w-pwc2: The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft
ghsa_unreviewed·2022-05-05
CVE-2013-0005 [HIGH] CWE-20 GHSA-j63h-6q3w-pwc2: The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft
The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Framework 3.5, 3.5 SP1, 3.5.1, and 4, and the Management OData IIS Extension on Windows Server 2012, allows remote attackers to cause a denial of service (resource consumption and daemon restart) via crafted values in HTTP requests, aka "Replace Denial of Service Vulnerability."
Kernel
HID: zeroplus: validate output report details
kernel_security·2013-09-11·CVSS 4.7
CVE-2013-2889 [MEDIUM] HID: zeroplus: validate output report details
HID: zeroplus: validate output report details
The zeroplus HID driver was not checking the size of allocated values
in fields it used. A HID device could send a malicious output report
that would cause the driver to write beyond the output report allocation
during initialization, causing a heap overflow:
[ 1442.728680] usb 1-1: New USB device found, idVendor=0c12, idProduct=0005
...
[ 1466.243173] BUG kmalloc-192 (Tainted: G W ): Redzone overwritten
CVE-2013-2889
Signed-off-by: Kees Cook
Cc: [email protected]
Reviewed-by: Benjamin Tissoires
Signed-off-by: Jiri Kosina
No detection rules found.
No public exploits indexed.
http://www.us-cert.gov/cas/techalerts/TA13-008A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-007https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16282http://www.us-cert.gov/cas/techalerts/TA13-008A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-007https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16282
2013-01-09
Published