CVE-2013-1950
The svc_dg_getargs function in libtirpc 0.2.3 and earlier allows remote attackers to cause a denial of service (rpcbind crash) via a Sun RPC request with crafted arguments that trigger a free of an invalid pointer.
- Affected products
- Alt Linux, Centos, Red Hat, Libtirpc, Libtirpc-Debuginfo, Libtirpc-Devel
- Libtirpc Project Libtirpc
- ≤ 0.2.3, 0.1.8, 0.1.9, 0.1.10, 0.1.11, 0.2.0, 0.2.1, 0.2.2
- Fix
- Available
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 6.5% (93th percentile)
- Weakness
- CWE-399
- NVD status
- Modified
- Published
- 2013-07-09
CVE-2013-1950 at NVD
3 known exploits for CVE-2013-1950
Proof-of-concept code and exploit modules indexed by Sploitus