CVE-2013-7039

Stack-based buffer overflow in the MHD_digest_auth_check function in libmicrohttpd before 0.9.32, when MHD_OPTION_CONNECTION_MEMORY_LIMIT is set to a large value, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long URI in an authentication header.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gnu:libmicrohttpd:*:*:*:*:*:*:*:*
cpe:2.3:a:gnu:libmicrohttpd:0.9.16:*:*:*:*:*:*:*
cpe:2.3:a:gnu:libmicrohttpd:0.9.17:*:*:*:*:*:*:*
cpe:2.3:a:gnu:libmicrohttpd:0.9.18:*:*:*:*:*:*:*
cpe:2.3:a:gnu:libmicrohttpd:0.9.19:*:*:*:*:*:*:*
cpe:2.3:a:gnu:libmicrohttpd:0.9.20:*:*:*:*:*:*:*
cpe:2.3:a:gnu:libmicrohttpd:0.9.21:*:*:*:*:*:*:*
cpe:2.3:a:gnu:libmicrohttpd:0.9.22:*:*:*:*:*:*:*
cpe:2.3:a:gnu:libmicrohttpd:0.9.23:*:*:*:*:*:*:*
cpe:2.3:a:gnu:libmicrohttpd:0.9.24:*:*:*:*:*:*:*
cpe:2.3:a:gnu:libmicrohttpd:0.9.25:*:*:*:*:*:*:*
cpe:2.3:a:gnu:libmicrohttpd:0.9.26:*:*:*:*:*:*:*
cpe:2.3:a:gnu:libmicrohttpd:0.9.27:*:*:*:*:*:*:*
cpe:2.3:a:gnu:libmicrohttpd:0.9.28:*:*:*:*:*:*:*
cpe:2.3:a:gnu:libmicrohttpd:0.9.29:*:*:*:*:*:*:*
cpe:2.3:a:gnu:libmicrohttpd:0.9.30:*:*:*:*:*:*:*

History

21 Nov 2024, 02:00

Type Values Removed Values Added
References () http://secunia.com/advisories/55903 - Vendor Advisory () http://secunia.com/advisories/55903 - Vendor Advisory
References () http://security.gentoo.org/glsa/glsa-201402-01.xml - () http://security.gentoo.org/glsa/glsa-201402-01.xml -
References () http://www.openwall.com/lists/oss-security/2013/12/09/11 - () http://www.openwall.com/lists/oss-security/2013/12/09/11 -
References () http://www.securityfocus.com/bid/64138 - () http://www.securityfocus.com/bid/64138 -
References () https://bugs.gentoo.org/show_bug.cgi?id=493450 - () https://bugs.gentoo.org/show_bug.cgi?id=493450 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=1039390 - () https://bugzilla.redhat.com/show_bug.cgi?id=1039390 -
References () https://gnunet.org/svn/libmicrohttpd/ChangeLog - () https://gnunet.org/svn/libmicrohttpd/ChangeLog -

Information

Published : 2013-12-13 18:55

Updated : 2024-11-21 02:00


NVD link : CVE-2013-7039

Mitre link : CVE-2013-7039

CVE.ORG link : CVE-2013-7039


JSON object : View

Products Affected

gnu

  • libmicrohttpd
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer