CVE-2013-2020
published 2013-05-13CVE-2013-2020: Integer underflow in the cli_scanpe function in pe.c in ClamAV before 0.97.8 allows remote attackers to cause a denial of service (crash) via a skewed offset…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.55%
88.1th percentile
Integer underflow in the cli_scanpe function in pe.c in ClamAV before 0.97.8 allows remote attackers to cause a denial of service (crash) via a skewed offset larger than the size of the PE section in a UPX packed executable, which triggers an out-of-bounds read.
Affected
52 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| clamav | clamav | <= 0.97.7 | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
ghsa7.5HIGH
osv5.0MEDIUM
vendor_redhat6.8MEDIUM
vendor_debian5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
php: multiple vulnerabilities in gdImageCrop()
vendor_redhat·2014-02-06·CVSS 6.8
CVE-2014-2020 [MEDIUM] php: multiple vulnerabilities in gdImageCrop()
php: multiple vulnerabilities in gdImageCrop()
ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not check data types, which might allow remote attackers to obtain sensitive information by using a (1) string or (2) array data type in place of a numeric data type, as demonstrated by an imagecrop function call with a string for the x dimension value, a different vulnerability than CVE-2013-7226.
Statement: Not vulnerable. This issue did not affect the versions of php or php53 as shipped with Red Hat Enterprise Linux 5 and 6, and the versions of php54-php as shipped with Red Hat Software Collections 1, as they did not include the vulnerable function (it was introduced in PHP 5.5.0).
Package: php (Red Hat Enterprise Linux 4) - Not affected
Package: gd (Red Hat Enterprise Linux 5) - Not affected
Ubuntu
ClamAV vulnerabilities
vendor_ubuntu·2013-05-03·CVSS 5.0
CVE-2013-2020 [MEDIUM] ClamAV vulnerabilities
Title: ClamAV vulnerabilities
Summary: ClamAV could be made to crash or run programs if it opened a specially
crafted file.
It was discovered that ClamAV would incorrectly parse a UPX-packed
executable, leading to possible inappropriate heap reads. An attacker
could use this issue to cause ClamAV to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2013-2020)
It was discovered that ClamAV would incorrectly parse a PDF document,
potentially writing beyond the size of a static array. An attacker could
use this issue to cause ClamAV to crash, resulting in a denial of service,
or possibly execute arbitrary code. (CVE-2013-2021)
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need
Debian
CVE-2013-2020: clamav - Integer underflow in the cli_scanpe function in pe.c in ClamAV before 0.97.8 all...
vendor_debian·2013·CVSS 5.0
CVE-2013-2020 [MEDIUM] CVE-2013-2020: clamav - Integer underflow in the cli_scanpe function in pe.c in ClamAV before 0.97.8 all...
Integer underflow in the cli_scanpe function in pe.c in ClamAV before 0.97.8 allows remote attackers to cause a denial of service (crash) via a skewed offset larger than the size of the PE section in a UPX packed executable, which triggers an out-of-bounds read.
Scope: local
bookworm: resolved (fixed in 0.97.8+dfsg-1)
bullseye: resolved (fixed in 0.97.8+dfsg-1)
forky: resolved (fixed in 0.97.8+dfsg-1)
sid: resolved (fixed in 0.97.8+dfsg-1)
trixie: resolved (fixed in 0.97.8+dfsg-1)
GHSA
GHSA-3fch-7wxv-99j8: Integer underflow in the cli_scanpe function in pe
ghsa_unreviewed·2022-05-17
CVE-2013-2020 [MEDIUM] GHSA-3fch-7wxv-99j8: Integer underflow in the cli_scanpe function in pe
Integer underflow in the cli_scanpe function in pe.c in ClamAV before 0.97.8 allows remote attackers to cause a denial of service (crash) via a skewed offset larger than the size of the PE section in a UPX packed executable, which triggers an out-of-bounds read.
GHSA
Unsafe object creation in json RubyGem
ghsa·2020-07-27·CVSS 7.5
CVE-2020-10663 [HIGH] CWE-20 Unsafe object creation in json RubyGem
Unsafe object creation in json RubyGem
The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269/GHSA-x457-cw4h-hq5f, but does not rely on poor garbage-collection behavior within Ruby. Specifically, use of JSON parsing methods can lead to creation of a malicious object within the interpreter, with adverse effects that are application-dependent.
OSV
CVE-2013-2020: Integer underflow in the cli_scanpe function in pe
osv·2013-05-13·CVSS 5.0
CVE-2013-2020 [MEDIUM] CVE-2013-2020: Integer underflow in the cli_scanpe function in pe
Integer underflow in the cli_scanpe function in pe.c in ClamAV before 0.97.8 allows remote attackers to cause a denial of service (crash) via a skewed offset larger than the size of the PE section in a UPX packed executable, which triggers an out-of-bounds read.
Suricata
ET EXPLOIT D-Link IP Camera Vulnerable HTTP Request (CVE-2013-1601)
suricata·2014-11-25·CVSS 5.3
CVE-2013-1601 [MEDIUM] ET EXPLOIT D-Link IP Camera Vulnerable HTTP Request (CVE-2013-1601)
ET EXPLOIT D-Link IP Camera Vulnerable HTTP Request (CVE-2013-1601)
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET EXPLOIT D-Link IP Camera Vulnerable HTTP Request (CVE-2013-1601)"; flow:established,to_server; urilen:12; http.method; content:"GET"; http.uri; content:"/md/lums.cgi"; fast_pattern; reference:url,www.coresecurity.com/advisories/d-link-ip-cameras-multiple-vulnerabilities; classtype:attempted-admin; sid:2019803; rev:4; metadata:created_at 2014_11_25, cve CVE_2013_1601, signature_severity Major, updated_at 2020_09_28;)
Suricata
ET EXPLOIT D-Link IP Camera Vulnerable HTTP Request (CVE-2013-1599)
suricata·2014-11-25·CVSS 9.8
CVE-2013-1599 [CRITICAL] ET EXPLOIT D-Link IP Camera Vulnerable HTTP Request (CVE-2013-1599)
ET EXPLOIT D-Link IP Camera Vulnerable HTTP Request (CVE-2013-1599)
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET EXPLOIT D-Link IP Camera Vulnerable HTTP Request (CVE-2013-1599)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/cgi-bin/rtpd.cgi?"; fast_pattern; reference:url,www.coresecurity.com/advisories/d-link-ip-cameras-multiple-vulnerabilities; classtype:attempted-admin; sid:2019801; rev:4; metadata:created_at 2014_11_25, cve CVE_2013_1599, signature_severity Major, updated_at 2020_09_28;)
Exploit-DB
IcoFX 2.6 - '.ico' Buffer Overflow SEH + DEP Bypass using JOP
exploitdb·2021-06-07·CVSS 9.3
CVE-2013-4988 [CRITICAL] IcoFX 2.6 - '.ico' Buffer Overflow SEH + DEP Bypass using JOP
IcoFX 2.6 - '.ico' Buffer Overflow SEH + DEP Bypass using JOP
---
# Exploit Title: IcoFX 2.6 - '.ico' Buffer Overflow SEH + DEP Bypass using JOP
# Date: 2020-05-20
# Exploit Author: Austin Babcock
# Vendor Homepage: https://icofx.ro/
# Software Link: https://drive.google.com/file/d/1SONzNStA_W3pAPU5IUvsYS3z0jYymEZn/view?usp=sharing
# Version: 2.6.0.0
# Tested on: Windows 7 Ultimate x64
# CVE: CVE-2013-4988
# Steps: 1. Run script 2. Open application 3. Open maliciousJOP.ico via file -> open dropdown menu
# Payload Length: 1626 bytes
#While this is an older CVE, it is very rare to have a JOP chain available for a binary which is what this exploit attempts to demonstrate.
#Gadgets were found using the JOP ROCKET tool which is available at https://github.com/Bw3ll/JOP_ROCKET
#This exploi
Exploit-DB
Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution
exploitdb·2020-10-20·CVSS 9.8
CVE-2013-2251 [CRITICAL] Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution
Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution
---
# Exploit Title: Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution
# Google Dork: ext:action | filetype:action
# Date: 2020/09/09
# Exploit Author: Jonatas Fil
# Vendor Homepage: http://struts.apache.org/release/2.3.x/docs/s2-016.html
# Version: <= 2.3.15
# Tested on: Linux
# CVE : CVE-2013-2251
#!/usr/bin/python
#
# coding=utf-8
#
# Struts 2 DefaultActionMapper Exploit [S2-016]
# Interactive Shell for CVE-2013-2251
#
# The Struts 2 DefaultActionMapper supports a method for short-circuit
navigation state changes by prefixing parameters with
# "action:" or "redirect:", followed by a desired navigational target
expression. This mechanism was intended to help with
# attaching navigational information to
Exploit-DB
UBICOD Medivision Digital Signage 1.5.1 - Authorization Bypass
exploitdb·2020-07-23
UBICOD Medivision Digital Signage 1.5.1 - Authorization Bypass
UBICOD Medivision Digital Signage 1.5.1 - Authorization Bypass
---
# Title: UBICOD Medivision Digital Signage 1.5.1 - Authorization Bypass
# Date: 2020-07-23
# Author: LiquidWorm
# Product web page: http://www.medivision.co.kr
# CVE: N/A
Vendor: UBICOD Co., Ltd. | MEDIVISION INC.
Product web page: http://www.medivision.co.kr
Affected version: Firmware 1.5.1 (2013.01.3)
Summary: Medivision is a service that provides everything from DID operation to
development of DID (Digital Information Display) optimized for hospital environment
and production of professional contents, through DID product installation, image,
video content planning, design work, and remote control. This is a one-stop solution
that solves management at once.
Desc: The application suffers from a privilege escalation vu
Bugzilla
CVE-2013-7489 python-beaker: Deserialization of Untrusted Data which can lead to Arbitrary code execution
bugzilla·2020-06-23·CVSS 6.8
CVE-2013-7489 [MEDIUM] CVE-2013-7489 python-beaker: Deserialization of Untrusted Data which can lead to Arbitrary code execution
CVE-2013-7489 python-beaker: Deserialization of Untrusted Data which can lead to Arbitrary code execution
python-beaker is affected by Deserialization of untrusted data which could lead to Arbitrary code execution.
References:
https://github.com/bbangert/beaker/issues/191
https://www.openwall.com/lists/oss-security/2020/05/14/11
Discussion:
Created python-beaker tracking bugs for this issue:
Affects: fedora-all [bug 1850106]
---
*** Bug 1849014 has been marked as a duplicate of this bug. ***
---
Flaw summary:
If an attacker is able to enter malicious payloads into the cache database (e.g. if they are on the network and have creds for the database), they could get remote code execution on the machine running Beaker due to deserialization of data from the cache database by Pickle.
Bugzilla
CVE-2013-2020 CVE-2013-2021 clamav: Multiple potential security issues fixed in upstream 0.97.8 version
bugzilla·2013-04-24·CVSS 5.0
CVE-2013-2020 [MEDIUM] CVE-2013-2020 CVE-2013-2021 clamav: Multiple potential security issues fixed in upstream 0.97.8 version
CVE-2013-2020 CVE-2013-2021 clamav: Multiple potential security issues fixed in upstream 0.97.8 version
Clam AntiVirus upstream has released 0.97.8 version correcting couple of potential security bugs:
[1] http://blog.clamav.net/2013/04/clamav-0978-has-been-released.html
[2] https://github.com/vrtadmin/clamav-devel/blob/0.97/ChangeLog
Discussion:
These issues affect the versions of the clamav package, as shipped with Fedora release of 17 and 18. Please schedule an update.
--
These issues did NOT affect the version of the clamav package, as shipped with Fedora EPEL 6 (it has been updated to clamav-0.97.8-1.el6 version already).
--
These issues affect the version of the clamav package, as shipped with Fedora EPEL 5. Please schedule an update.
---
Created clamav tracking bugs for thi
http://blog.clamav.net/2013/04/clamav-0978-has-been-released.htmlhttp://lists.apple.com/archives/security-announce/2013/Sep/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2013/Sep/msg00004.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-June/109514.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-June/109639.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-June/109652.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-May/105575.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-12/msg00006.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00018.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00020.htmlhttp://secunia.com/advisories/53150http://secunia.com/advisories/53182http://support.apple.com/kb/HT5880http://support.apple.com/kb/HT5892http://www.mandriva.com/security/advisories?name=MDVSA-2013:159http://www.openwall.com/lists/oss-security/2013/04/25/2http://www.openwall.com/lists/oss-security/2013/04/29/20http://www.securityfocus.com/bid/59434http://www.ubuntu.com/usn/USN-1816-1https://bugzilla.clamav.net/show_bug.cgi?id=7055https://github.com/vrtadmin/clamav-devel/commit/270e368b99e93aa5447d46c797c92c3f9f39f375http://blog.clamav.net/2013/04/clamav-0978-has-been-released.htmlhttp://lists.apple.com/archives/security-announce/2013/Sep/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2013/Sep/msg00004.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-June/109514.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-June/109639.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-June/109652.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-May/105575.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-12/msg00006.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00018.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00020.htmlhttp://secunia.com/advisories/53150http://secunia.com/advisories/53182http://support.apple.com/kb/HT5880http://support.apple.com/kb/HT5892http://www.mandriva.com/security/advisories?name=MDVSA-2013:159http://www.openwall.com/lists/oss-security/2013/04/25/2http://www.openwall.com/lists/oss-security/2013/04/29/20http://www.securityfocus.com/bid/59434http://www.ubuntu.com/usn/USN-1816-1https://bugzilla.clamav.net/show_bug.cgi?id=7055https://github.com/vrtadmin/clamav-devel/commit/270e368b99e93aa5447d46c797c92c3f9f39f375
2013-05-13
Published