CVE-2013-1001
published 2013-05-20CVE-2013-1001: WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and…
PriorityP337critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
2.74%
84.5th percentile
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
Affected
127 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iphone_os | <= 6.1.4 | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r5xv-c23q-gmv3: WebKit, as used in Apple iTunes before 11
ghsa_unreviewed·2022-05-14
CVE-2013-1001 [HIGH] GHSA-r5xv-c23q-gmv3: WebKit, as used in Apple iTunes before 11
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
OSV
CVE-2013-1001: WebKit, as used in Apple iTunes before 11
osv·2013-05-20·CVSS 9.3
CVE-2013-1001 [CRITICAL] CVE-2013-1001: WebKit, as used in Apple iTunes before 11
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
No detection rules found.
Talos
VRT-2013-1001 (CVE-2013-6487): Buffer overflow in Gadu-Gadu HTTP parsing
blogs_talos·2014-01-28·CVSS 7.5
CVE-2013-6487 [HIGH] VRT-2013-1001 (CVE-2013-6487): Buffer overflow in Gadu-Gadu HTTP parsing
## VRT-2013-1001 (CVE-2013-6487): Buffer overflow in Gadu-Gadu HTTP parsing
## Sourcefire Vulnerability Report VRT-2013-1001 (CVE-2013-6487): Buffer overflow in Gadu-Gadu HTTP parsing
## Description An exploitable remote code execution vulnerability exists in Pidgin's implementation of the Gadu Gadu protocol in the libpurple library. An attacker who can control the Content-Length of a HTTP request can cause an undersized allocation which can later be used to overflow into the heap. An attack requires the ability to spoof messages from the gadu-gadu.pl domain to exploit this vulnerability.
## Tested Versions Pidgin 2.10.7
## Coverage Prior coverage through an http_inspect alert GID 120, SID 8 as well as SID 2580.
Talos
VRT-2013-1001 (CVE-2013-6487): Buffer overflow in Gadu-Gadu HTTP parsing
blogs_talos·2014-01-28·CVSS 7.5
CVE-2013-6487 [HIGH] VRT-2013-1001 (CVE-2013-6487): Buffer overflow in Gadu-Gadu HTTP parsing
### Sourcefire Vulnerability Report VRT-2013-1001 (CVE-2013-6487): Buffer overflow in Gadu-Gadu HTTP parsing
#### Description An exploitable remote code execution vulnerability exists in Pidgin's implementation of the Gadu Gadu protocol in the libpurple library. An attacker who can control the Content-Length of a HTTP request can cause an undersized allocation which can later be used to overflow into the heap. An attack requires the ability to spoof messages from the gadu-gadu.pl domain to exploit this vulnerability.
#### Tested Versions Pidgin 2.10.7
#### Coverage Prior coverage through an http_inspect alert GID 120, SID 8 as well as SID 2580.
#### Details In gg_http_watch_fd() in file pidgin-2.10.7\libpurple\protocols\gg\lib\http.c at line 353 content-length will be read from the HTT
http://lists.apple.com/archives/security-announce/2013/Jun/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2013/May/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2013/Sep/msg00006.htmlhttp://secunia.com/advisories/54886http://support.apple.com/kb/HT5766http://support.apple.com/kb/HT5785http://support.apple.com/kb/HT5934https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17572http://lists.apple.com/archives/security-announce/2013/Jun/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2013/May/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2013/Sep/msg00006.htmlhttp://secunia.com/advisories/54886http://support.apple.com/kb/HT5766http://support.apple.com/kb/HT5785http://support.apple.com/kb/HT5934https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17572
2013-05-20
Published