CVE-2013-4391
published 2013-10-28CVE-2013-4391: Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows remote attackers to cause a denial of service (crash) and…
PriorityP340high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
5.34%
91.7th percentile
Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large journal data field, which triggers a heap-based buffer overflow.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | systemd | < systemd 204-5 (bookworm) | systemd 204-5 (bookworm) |
| systemd_project | systemd | < 190 | 190 |
| systemd_project | systemd | >= 0 < 204-5 | 204-5 |
| systemd_project | systemd | >= 0 < 204-5 | 204-5 |
| systemd_project | systemd | >= 0 < 204-5 | 204-5 |
| systemd_project | systemd | >= 0 < 204-5 | 204-5 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5jjc-6f35-8hmp: Integer overflow in the valid_user_field function in journal/journald-native
ghsa_unreviewed·2022-05-13
CVE-2013-4391 [HIGH] CWE-190 GHSA-5jjc-6f35-8hmp: Integer overflow in the valid_user_field function in journal/journald-native
Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large journal data field, which triggers a heap-based buffer overflow.
OSV
CVE-2013-4391: Integer overflow in the valid_user_field function in journal/journald-native
osv·2013-10-28·CVSS 7.5
CVE-2013-4391 [HIGH] CVE-2013-4391: Integer overflow in the valid_user_field function in journal/journald-native
Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large journal data field, which triggers a heap-based buffer overflow.
Red Hat
systemd: Integer overflow, leading to heap-based buffer overflow by processing native messages
vendor_redhat·2013-09-23·CVSS 7.5
CVE-2013-4391 [HIGH] CWE-190 systemd: Integer overflow, leading to heap-based buffer overflow by processing native messages
systemd: Integer overflow, leading to heap-based buffer overflow by processing native messages
Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large journal data field, which triggers a heap-based buffer overflow.
Package: systemd (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-4391: systemd - Integer overflow in the valid_user_field function in journal/journald-native.c i...
vendor_debian·2013·CVSS 7.5
CVE-2013-4391 [HIGH] CVE-2013-4391: systemd - Integer overflow in the valid_user_field function in journal/journald-native.c i...
Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large journal data field, which triggers a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 204-5)
bullseye: resolved (fixed in 204-5)
forky: resolved (fixed in 204-5)
sid: resolved (fixed in 204-5)
trixie: resolved (fixed in 204-5)
No detection rules found.
No public exploits indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=725357http://cgit.freedesktop.org/systemd/systemd/commit/?id=505b6a61c22d5565e9308045c7b9bf79f7d0517ehttp://www.debian.org/security/2013/dsa-2777http://www.openwall.com/lists/oss-security/2013/10/01/9https://bugzilla.redhat.com/show_bug.cgi?id=859051https://security.gentoo.org/glsa/201612-34http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=725357http://cgit.freedesktop.org/systemd/systemd/commit/?id=505b6a61c22d5565e9308045c7b9bf79f7d0517ehttp://www.debian.org/security/2013/dsa-2777http://www.openwall.com/lists/oss-security/2013/10/01/9https://bugzilla.redhat.com/show_bug.cgi?id=859051https://security.gentoo.org/glsa/201612-34
2013-10-28
Published