CVE-2013-0220
published 2013-02-24CVE-2013-0220: The (1) sss_autofs_cmd_getautomntent and (2) sss_autofs_cmd_getautomntbyname function in responder/autofs/autofssrv_cmd.c and the (3) ssh_cmd_parse_request…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.32%
87.3th percentile
The (1) sss_autofs_cmd_getautomntent and (2) sss_autofs_cmd_getautomntbyname function in responder/autofs/autofssrv_cmd.c and the (3) ssh_cmd_parse_request function in responder/ssh/sshsrv_cmd.c in System Security Services Daemon (SSSD) before 1.9.4 allow remote attackers to cause a denial of service (out-of-bounds read, crash, and restart) via a crafted SSSD packet.
Affected
78 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sssd | < sssd 1.8.4-2 (bookworm) | sssd 1.8.4-2 (bookworm) |
| fedoraproject | sssd | <= 1.9.3 | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
| fedoraproject | sssd | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
sssd: Out-of-bounds read flaws in autofs and ssh services responders
vendor_redhat·2013-01-23·CVSS 5.0
CVE-2013-0220 [MEDIUM] CWE-125 sssd: Out-of-bounds read flaws in autofs and ssh services responders
sssd: Out-of-bounds read flaws in autofs and ssh services responders
The (1) sss_autofs_cmd_getautomntent and (2) sss_autofs_cmd_getautomntbyname function in responder/autofs/autofssrv_cmd.c and the (3) ssh_cmd_parse_request function in responder/ssh/sshsrv_cmd.c in System Security Services Daemon (SSSD) before 1.9.4 allow remote attackers to cause a denial of service (out-of-bounds read, crash, and restart) via a crafted SSSD packet.
Package: sssd (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2013-0220: sssd - The (1) sss_autofs_cmd_getautomntent and (2) sss_autofs_cmd_getautomntbyname fun...
vendor_debian·2013·CVSS 5.0
CVE-2013-0220 [MEDIUM] CVE-2013-0220: sssd - The (1) sss_autofs_cmd_getautomntent and (2) sss_autofs_cmd_getautomntbyname fun...
The (1) sss_autofs_cmd_getautomntent and (2) sss_autofs_cmd_getautomntbyname function in responder/autofs/autofssrv_cmd.c and the (3) ssh_cmd_parse_request function in responder/ssh/sshsrv_cmd.c in System Security Services Daemon (SSSD) before 1.9.4 allow remote attackers to cause a denial of service (out-of-bounds read, crash, and restart) via a crafted SSSD packet.
Scope: local
bookworm: resolved (fixed in 1.8.4-2)
bullseye: resolved (fixed in 1.8.4-2)
forky: resolved (fixed in 1.8.4-2)
sid: resolved (fixed in 1.8.4-2)
trixie: resolved (fixed in 1.8.4-2)
GHSA
GHSA-jj7g-h828-6wpv: The (1) sss_autofs_cmd_getautomntent and (2) sss_autofs_cmd_getautomntbyname function in responder/autofs/autofssrv_cmd
ghsa_unreviewed·2022-05-05
CVE-2013-0220 [MEDIUM] CWE-119 GHSA-jj7g-h828-6wpv: The (1) sss_autofs_cmd_getautomntent and (2) sss_autofs_cmd_getautomntbyname function in responder/autofs/autofssrv_cmd
The (1) sss_autofs_cmd_getautomntent and (2) sss_autofs_cmd_getautomntbyname function in responder/autofs/autofssrv_cmd.c and the (3) ssh_cmd_parse_request function in responder/ssh/sshsrv_cmd.c in System Security Services Daemon (SSSD) before 1.9.4 allow remote attackers to cause a denial of service (out-of-bounds read, crash, and restart) via a crafted SSSD packet.
OSV
CVE-2013-0220: The (1) sss_autofs_cmd_getautomntent and (2) sss_autofs_cmd_getautomntbyname function in responder/autofs/autofssrv_cmd
osv·2013-02-24·CVSS 5.0
CVE-2013-0220 [MEDIUM] CVE-2013-0220: The (1) sss_autofs_cmd_getautomntent and (2) sss_autofs_cmd_getautomntbyname function in responder/autofs/autofssrv_cmd
The (1) sss_autofs_cmd_getautomntent and (2) sss_autofs_cmd_getautomntbyname function in responder/autofs/autofssrv_cmd.c and the (3) ssh_cmd_parse_request function in responder/ssh/sshsrv_cmd.c in System Security Services Daemon (SSSD) before 1.9.4 allow remote attackers to cause a denial of service (out-of-bounds read, crash, and restart) via a crafted SSSD packet.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-0220 CVE-2013-0219 sssd various flaws [fedora-all]
bugzilla·2013-01-23·CVSS 3.7
CVE-2013-0220 [LOW] CVE-2013-0220 CVE-2013-0219 sssd various flaws [fedora-all]
CVE-2013-0220 CVE-2013-0219 sssd various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multiple supp
Bugzilla
CVE-2012-6073 Jenkins: open redirect
bugzilla·2012-12-28·CVSS 5.8
CVE-2012-6073 [MEDIUM] CVE-2012-6073 Jenkins: open redirect
CVE-2012-6073 Jenkins: open redirect
Jenkins Security Advisory 2012-11-20
The second vulnerability is so-called open redirect vulnerability. This
allows an anonymous attacker to create an URL that looks as if it's pointing
to Jenkins, yet it actually lands on the site that the attacker controls.
This can be therefore used as a basis for phishing.
Fix:
Main line users should upgrade to Jenkins 1.491
LTS users should upgrade to 1.480.1
External URLs:
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2012-11-20
http://www.cloudbees.com/jenkins-advisory/jenkins-security-advisory-2012-11-20.cb
Discussion:
This issue has been addressed in following products:
RHEL 6 Version of OpenShift Enterprise
Via RHSA-2013:0220 https://rhn.redhat.com/errata/RHSA-2013-0220.html
Bugzilla
CVE-2012-6074 Jenkins: cross-site scripting vulnerability
bugzilla·2012-12-28·CVSS 3.5
CVE-2012-6074 [LOW] CVE-2012-6074 Jenkins: cross-site scripting vulnerability
CVE-2012-6074 Jenkins: cross-site scripting vulnerability
Jenkins Security Advisory 2012-11-20
The third vulnerability is a cross-site scripting vulnerability that allows
an attacker with some degree of write access in Jenkins to embed malicious
JavaScript into pages generated by Jenkins.
Fix:
Main line users should upgrade to Jenkins 1.491
LTS users should upgrade to 1.480.1
External URLs:
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2012-11-20
http://www.cloudbees.com/jenkins-advisory/jenkins-security-advisory-2012-11-20.cb
Discussion:
This issue has been addressed in following products:
RHEL 6 Version of OpenShift Enterprise
Via RHSA-2013:0220 https://rhn.redhat.com/errata/RHSA-2013-0220.html
Bugzilla
CVE-2012-5658 OpenShift Origin: rhc-chk.rb password exposure in log files
bugzilla·2012-12-20·CVSS 2.1
CVE-2012-5658 [LOW] CVE-2012-5658 OpenShift Origin: rhc-chk.rb password exposure in log files
CVE-2012-5658 OpenShift Origin: rhc-chk.rb password exposure in log files
It is reported that the rhc-chk command when run with the -d displays the
password in cleartext.
Discussion:
This issue has been addressed in following products:
RHEL 6 Version of OpenShift Enterprise
Via RHSA-2013:0220 https://rhn.redhat.com/errata/RHSA-2013-0220.html
Bugzilla
CVE-2013-0220 sssd: Out-of-bounds read flaws in autofs and ssh services responders
bugzilla·2012-12-06·CVSS 5.0
CVE-2013-0220 [MEDIUM] CVE-2013-0220 sssd: Out-of-bounds read flaws in autofs and ssh services responders
CVE-2013-0220 sssd: Out-of-bounds read flaws in autofs and ssh services responders
Multiple out-of-buffer bounds read flaws were found in the way autofs and ssh service responders of sssd, a System Security Services Daemon, performed parsing of SSSD packet values. An attacker could provide a specially-crafted packet that, when processed by the autofs or ssh service responders of sssd would lead to sssd server crash (temporary denial of service).
This issue was found by Florian Weimer of Red Hat Product Security Team.
Discussion:
This issue did NOT affect the version of the sssd package, as shipped with Red Hat Enterprise Linux 5 as it did not include support for autofs and ssh responders yet.
--
This issue affects the version of the sssd package, as shipped with Red Hat Enterprise Li
http://git.fedorahosted.org/cgit/sssd.git/commit/?id=2bd514cfde1938b1e245af11c9b548d58d49b325http://git.fedorahosted.org/cgit/sssd.git/commit/?id=30e2585dd46b62aa3a4abdf6de3f40a20e1743abhttp://lists.fedoraproject.org/pipermail/package-announce/2013-February/098434.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-February/098613.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0508.htmlhttp://secunia.com/advisories/51928http://secunia.com/advisories/52315http://www.securityfocus.com/bid/57539https://bugzilla.redhat.com/show_bug.cgi?id=884601https://fedorahosted.org/sssd/ticket/1781https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.4http://git.fedorahosted.org/cgit/sssd.git/commit/?id=2bd514cfde1938b1e245af11c9b548d58d49b325http://git.fedorahosted.org/cgit/sssd.git/commit/?id=30e2585dd46b62aa3a4abdf6de3f40a20e1743abhttp://lists.fedoraproject.org/pipermail/package-announce/2013-February/098434.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-February/098613.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0508.htmlhttp://secunia.com/advisories/51928http://secunia.com/advisories/52315http://www.securityfocus.com/bid/57539https://bugzilla.redhat.com/show_bug.cgi?id=884601https://fedorahosted.org/sssd/ticket/1781https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.4
2013-02-24
Published