cbcvebase.
CVE-2013-4550
published 2013-12-24

CVE-2013-4550: Bip before 0.8.9, when running as a daemon, writes SSL handshake errors to an unexpected file descriptor that was previously associated with stderr before…

PriorityP426medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EPSS
2.22%
80.7th percentile
Bip before 0.8.9, when running as a daemon, writes SSL handshake errors to an unexpected file descriptor that was previously associated with stderr before stderr has been closed, which allows remote attackers to write to other sockets and have an unspecified impact via a failed SSL handshake, a different vulnerability than CVE-2011-5268. NOTE: some sources originally mapped this CVE to two different types of issues; this CVE has since been SPLIT, producing CVE-2011-5268.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianbip< bip 0.8.9-1 (bookworm)bip 0.8.9-1 (bookworm)
duckcorpbip<= 0.8.8
duckcorpbip
duckcorpbip
duckcorpbip
duckcorpbip
duckcorpbip
duckcorpbip
duckcorpbip
duckcorpbip
duckcorpbip>= 0 < 0.8.9-10.8.9-1
duckcorpbip>= 0 < 0.8.9-10.8.9-1
duckcorpbip>= 0 < 0.8.9-10.8.9-1
duckcorpbip>= 0 < 0.8.9-10.8.9-1
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora

CVSS provenance

nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.