« Volver al listado

CVE-2013-1747

Estado: ModificadaMedia (5)—

channel.c in ngIRCd 20 and 20.1 allows remote attackers to cause a denial of service (assertion failure and crash) via a KICK command for a user who is not on the associated channel.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-1747",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2013-03-28T23:55:01.717",
  "references": [
    {
      "url": "http://arthur.barton.de/pipermail/ngircd-ml/2013-February/000623.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://arthur.barton.de/pipermail/ngircd-ml/2013-February/000625.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101706.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://ngircd.barton.de/doc/NEWS",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/52982",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.com/show/osvdb/91836",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://arthur.barton.de/cgi-bin/gitweb.cgi?p=ngircd.git%3Bh=0e63fb3fa7ac4ca048e8c2b648d2be3fd0572311",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://arthur.barton.de/pipermail/ngircd-ml/2013-February/000623.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://arthur.barton.de/pipermail/ngircd-ml/2013-February/000625.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101706.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://ngircd.barton.de/doc/NEWS",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/52982",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.com/show/osvdb/91836",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://arthur.barton.de/cgi-bin/gitweb.cgi?p=ngircd.git%3Bh=0e63fb3fa7ac4ca048e8c2b648d2be3fd0572311",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "channel.c in ngIRCd 20 and 20.1 allows remote attackers to cause a denial of service (assertion failure and crash) via a KICK command for a user who is not on the associated channel."
    },
    {
      "lang": "es",
      "value": "channel.c en ngIRCd v20 y v20.1, permite a atacantes remotos provocar una denegación de servicio (error de aserción y caída) mediante un comando KICK para un usuario que no está en el canal asociado."
    }
  ],
  "lastModified": "2026-06-16T23:52:03.087",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ngircd:ngircd:20:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CC0E291E-08C1-4639-B2D8-D3E4B3BFDF57"
            },
            {
              "criteria": "cpe:2.3:a:ngircd:ngircd:20.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D65E29D0-320D-41F8-8243-FC140D8060DC"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}