CVE-2013-7039
published 2013-12-13CVE-2013-7039: Stack-based buffer overflow in the MHD_digest_auth_check function in libmicrohttpd before 0.9.32, when MHD_OPTION_CONNECTION_MEMORY_LIMIT is set to a large…
PriorityP432medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EPSS
3.28%
87.0th percentile
Stack-based buffer overflow in the MHD_digest_auth_check function in libmicrohttpd before 0.9.32, when MHD_OPTION_CONNECTION_MEMORY_LIMIT is set to a large value, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long URI in an authentication header.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libmicrohttpd | < libmicrohttpd 0.9.32-1 (bookworm) | libmicrohttpd 0.9.32-1 (bookworm) |
| gnu | libmicrohttpd | <= 0.9.31 | — |
| gnu | libmicrohttpd | — | — |
| gnu | libmicrohttpd | — | — |
| gnu | libmicrohttpd | — | — |
| gnu | libmicrohttpd | — | — |
| gnu | libmicrohttpd | — | — |
| gnu | libmicrohttpd | — | — |
| gnu | libmicrohttpd | — | — |
| gnu | libmicrohttpd | — | — |
| gnu | libmicrohttpd | — | — |
| gnu | libmicrohttpd | — | — |
| gnu | libmicrohttpd | — | — |
| gnu | libmicrohttpd | — | — |
| gnu | libmicrohttpd | — | — |
| gnu | libmicrohttpd | — | — |
| gnu | libmicrohttpd | — | — |
| gnu | libmicrohttpd | >= 0 < 0.9.32-1 | 0.9.32-1 |
| gnu | libmicrohttpd | >= 0 < 0.9.32-1 | 0.9.32-1 |
| gnu | libmicrohttpd | >= 0 < 0.9.32-1 | 0.9.32-1 |
| gnu | libmicrohttpd | >= 0 < 0.9.32-1 | 0.9.32-1 |
CVSS provenance
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv5.1MEDIUM
vendor_debian5.1LOW
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xjww-5jpx-q2w4: Stack-based buffer overflow in the MHD_digest_auth_check function in libmicrohttpd before 0
ghsa_unreviewed·2022-05-17
CVE-2013-7039 [MEDIUM] CWE-119 GHSA-xjww-5jpx-q2w4: Stack-based buffer overflow in the MHD_digest_auth_check function in libmicrohttpd before 0
Stack-based buffer overflow in the MHD_digest_auth_check function in libmicrohttpd before 0.9.32, when MHD_OPTION_CONNECTION_MEMORY_LIMIT is set to a large value, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long URI in an authentication header.
OSV
CVE-2013-7039: Stack-based buffer overflow in the MHD_digest_auth_check function in libmicrohttpd before 0
osv·2013-12-13·CVSS 5.1
CVE-2013-7039 [MEDIUM] CVE-2013-7039: Stack-based buffer overflow in the MHD_digest_auth_check function in libmicrohttpd before 0
Stack-based buffer overflow in the MHD_digest_auth_check function in libmicrohttpd before 0.9.32, when MHD_OPTION_CONNECTION_MEMORY_LIMIT is set to a large value, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long URI in an authentication header.
Red Hat
libmicrohttpd: stack overflow in MHD_digest_auth_check()
vendor_redhat·2013-11-28·CVSS 5.1
CVE-2013-7039 [MEDIUM] libmicrohttpd: stack overflow in MHD_digest_auth_check()
libmicrohttpd: stack overflow in MHD_digest_auth_check()
Stack-based buffer overflow in the MHD_digest_auth_check function in libmicrohttpd before 0.9.32, when MHD_OPTION_CONNECTION_MEMORY_LIMIT is set to a large value, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long URI in an authentication header.
Package: libmicrohttpd (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-7039: libmicrohttpd - Stack-based buffer overflow in the MHD_digest_auth_check function in libmicrohtt...
vendor_debian·2013·CVSS 5.1
CVE-2013-7039 [MEDIUM] CVE-2013-7039: libmicrohttpd - Stack-based buffer overflow in the MHD_digest_auth_check function in libmicrohtt...
Stack-based buffer overflow in the MHD_digest_auth_check function in libmicrohttpd before 0.9.32, when MHD_OPTION_CONNECTION_MEMORY_LIMIT is set to a large value, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long URI in an authentication header.
Scope: local
bookworm: resolved (fixed in 0.9.32-1)
bullseye: resolved (fixed in 0.9.32-1)
forky: resolved (fixed in 0.9.32-1)
sid: resolved (fixed in 0.9.32-1)
trixie: resolved (fixed in 0.9.32-1)
No detection rules found.
No public exploits indexed.
arXiv
CheckedCBox: Type Directed Program Partitioning with Checked C for Incremental Spatial Memory Safety
arxiv_fulltext·2023-02-03
CheckedCBox: Type Directed Program Partitioning with Checked C for Incremental Spatial Memory Safety
: Type Directed Program Partitioning with for Incremental Spatial Memory Safety (Extended Version)
: Type Directed Program Partitioning with for Incremental Spatial Memory Safety
Liyi Li^*, Arunkumar Bhattar^* ^ , Le Chang, Mingwei Zhu, and Aravind Machiry^
University of Maryland ^ Purdue University
## Abstract
Spatial memory safety violation is still a major issue for C programs.
Checked C is a safe dialect of C and extends it with checked pointer types and annotations that guarantee spatial memory safety in a backward compatible manner, allowing the mix of checked pointers and regular (unchecked) pointer types.
However, unchecked code vulnerabilities can violate the checked code's spatial safety guarantees.
We present , which adds a flexible, type directed program partitioning mech
Bugzilla
CVE-2013-7039 libmicrohttpd: stack overflow in MHD_digest_auth_check()
bugzilla·2013-12-09·CVSS 5.1
CVE-2013-7039 [MEDIUM] CVE-2013-7039 libmicrohttpd: stack overflow in MHD_digest_auth_check()
CVE-2013-7039 libmicrohttpd: stack overflow in MHD_digest_auth_check()
A stack overflow flaw was found in the MHD_digest_auth_check() function in libmicrohttpd. If MHD_OPTION_CONNECTION_MEMORY_LIMIT was configured to allow large allocations, a remote attacker could possibly use this flaw to cause an application using libmicrohttpd to crash or, potentially, execute arbitrary code with the privileges of the user running the application. This issue has been resolved in version 0.9.32.
References:
https://gnunet.org/svn/libmicrohttpd/ChangeLog
http://secunia.com/advisories/55903/
https://bugs.gentoo.org/show_bug.cgi?id=493450
Acknowledgements:
This issue was discovered by Florian Weimer of the Red Hat Product Security Team.
Discussion:
Created libmicrohttpd tracking bugs for this issue:
http://secunia.com/advisories/55903http://security.gentoo.org/glsa/glsa-201402-01.xmlhttp://www.openwall.com/lists/oss-security/2013/12/09/11http://www.securityfocus.com/bid/64138https://bugs.gentoo.org/show_bug.cgi?id=493450https://bugzilla.redhat.com/show_bug.cgi?id=1039390https://gnunet.org/svn/libmicrohttpd/ChangeLoghttp://secunia.com/advisories/55903http://security.gentoo.org/glsa/glsa-201402-01.xmlhttp://www.openwall.com/lists/oss-security/2013/12/09/11http://www.securityfocus.com/bid/64138https://bugs.gentoo.org/show_bug.cgi?id=493450https://bugzilla.redhat.com/show_bug.cgi?id=1039390https://gnunet.org/svn/libmicrohttpd/ChangeLog
2013-12-13
Published