CVE-2013-3706
published 2014-03-06CVE-2013-3706: Directory traversal vulnerability in the PreBoot service in Novell ZENworks Configuration Management (ZCM) 11.2 allows remote attackers to read arbitrary files…
PriorityP335medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
7.61%
93.8th percentile
Directory traversal vulnerability in the PreBoot service in Novell ZENworks Configuration Management (ZCM) 11.2 allows remote attackers to read arbitrary files via a .. (dot dot) in a preboot update pathname, aka ZDI-CAN-1595.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| novell | zenworks_configuration_management | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Novell ZENworks Configuration Management 11.2 PreBoot Service path traversal (ID 7014663 / Nessus ID 72814)
vuldb·2026-05-07·CVSS 5.0
CVE-2013-3706 [MEDIUM] Novell ZENworks Configuration Management 11.2 PreBoot Service path traversal (ID 7014663 / Nessus ID 72814)
A vulnerability categorized as problematic has been discovered in Novell ZENworks Configuration Management 11.2. The affected element is an unknown function of the component PreBoot Service. Such manipulation leads to path traversal.
This vulnerability is traded as CVE-2013-3706. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.
GHSA
GHSA-pg6v-35j6-x9ww: Directory traversal vulnerability in the PreBoot service in Novell ZENworks Configuration Management (ZCM) 11
ghsa_unreviewed·2022-05-17
CVE-2013-3706 [MEDIUM] CWE-22 GHSA-pg6v-35j6-x9ww: Directory traversal vulnerability in the PreBoot service in Novell ZENworks Configuration Management (ZCM) 11
Directory traversal vulnerability in the PreBoot service in Novell ZENworks Configuration Management (ZCM) 11.2 allows remote attackers to read arbitrary files via a .. (dot dot) in a preboot update pathname, aka ZDI-CAN-1595.
Red Hat
glibc: stack (frame) overflow in getaddrinfo() when called with AF_INET, AF_INET6 (incomplete fix for CVE-2013-4458)
vendor_redhat·2016-04-27·CVSS 5.0
CVE-2016-3706 [MEDIUM] CWE-121 glibc: stack (frame) overflow in getaddrinfo() when called with AF_INET, AF_INET6 (incomplete fix for CVE-2013-4458)
glibc: stack (frame) overflow in getaddrinfo() when called with AF_INET, AF_INET6 (incomplete fix for CVE-2013-4458)
Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in the GNU C Library (aka glibc or libc6) allows remote attackers to cause a denial of service (crash) via vectors involving hostent conversion. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4458.
Package: compat-glibc (Red Hat Enterprise Linux 5) - Not affected
Package: glibc (Red Hat Enterprise Linux 5) - Will not fix
Package: compat-glibc (Red Hat Enterprise Linux 6) - Not affected
Package: glibc (Red Hat Enterprise Linux 6) - Will not fix
Package: compat-glibc (Red Hat Enterprise Linux 7) - Not affected
Package: glibc (Red Hat Enterprise Linux 7) - No
No detection rules found.
No public exploits indexed.
2014-03-06
Published