CVE-2013-4685

Buffer overflow in flowd in Juniper Junos 10.4 before 10.4S14, 11.4 before 11.4R7, 12.1 before 12.1R6, and 12.1X44 before 12.1X44-D15 on SRX devices, when Captive Portal is enabled with the UAC enforcer role, allows remote attackers to execute arbitrary code via crafted HTTP requests, aka PR 849100.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:juniper:junos:10.4:*:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:11.4:*:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:12.1:*:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:12.1x44:*:*:*:*:*:*:*
OR cpe:2.3:h:juniper:srx100:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx110:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx1400:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx210:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx220:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx240:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx3400:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx3600:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx550:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx5600:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx5800:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx650:-:*:*:*:*:*:*:*

History

21 Nov 2024, 01:56

Type Values Removed Values Added
References () http://kb.juniper.net/JSA10574 - Vendor Advisory () http://kb.juniper.net/JSA10574 - Vendor Advisory
References () http://osvdb.org/95108 - () http://osvdb.org/95108 -
References () http://www.securityfocus.com/bid/61125 - () http://www.securityfocus.com/bid/61125 -

Information

Published : 2013-07-11 14:55

Updated : 2024-11-21 01:56


NVD link : CVE-2013-4685

Mitre link : CVE-2013-4685

CVE.ORG link : CVE-2013-4685


JSON object : View

Products Affected

juniper

  • srx100
  • srx1400
  • srx220
  • srx3400
  • srx110
  • srx3600
  • srx240
  • srx650
  • srx210
  • junos
  • srx5600
  • srx5800
  • srx550
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer