cbcvebase.
CVE-2013-1950
published 2013-07-09

CVE-2013-1950: The svc_dg_getargs function in libtirpc 0.2.3 and earlier allows remote attackers to cause a denial of service (rpcbind crash) via a Sun RPC request with…

PriorityP427medium4.3CVSS 2.0
AVNACMAuNCNINAP
EXPLOIT
EPSS
6.46%
92.9th percentile
The svc_dg_getargs function in libtirpc 0.2.3 and earlier allows remote attackers to cause a denial of service (rpcbind crash) via a Sun RPC request with crafted arguments that trigger a free of an invalid pointer.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlibtirpc
libtirpc_projectlibtirpc<= 0.2.3
libtirpc_projectlibtirpc
libtirpc_projectlibtirpc
libtirpc_projectlibtirpc
libtirpc_projectlibtirpc
libtirpc_projectlibtirpc
libtirpc_projectlibtirpc
libtirpc_projectlibtirpc

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.