« Volver al listado

CVE-2013-7401

Estado: ModificadaMedia (5)—

The parse_request function in request.c in c-icap 0.2.x allows remote attackers to cause a denial of service (crash) via a URI without a " " or "?" character in an ICAP request, as demonstrated by use of the OPTIONS method.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-7401",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-12-19T20:59:00.057",
  "references": [
    {
      "url": "http://advisories.mageia.org/MGASA-2014-0530.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://openwall.com/lists/oss-security/2014/09/15/6",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/ref/89/c-icap.txt",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://security.gentoo.org/glsa/glsa-201409-07.xml",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://sourceforge.net/p/c-icap/code/1018/",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2015:001",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/89304",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://advisories.mageia.org/MGASA-2014-0530.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://openwall.com/lists/oss-security/2014/09/15/6",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/ref/89/c-icap.txt",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://security.gentoo.org/glsa/glsa-201409-07.xml",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://sourceforge.net/p/c-icap/code/1018/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2015:001",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/89304",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The parse_request function in request.c in c-icap 0.2.x allows remote attackers to cause a denial of service (crash) via a URI without a \" \" or \"?\" character in an ICAP request, as demonstrated by use of the OPTIONS method."
    },
    {
      "lang": "es",
      "value": "La función parse_request en request.c en c-icap 0.2.x permite a atacantes remotos provocar una denegación de servicio (caída) a través de una URI sin un caracter ' ' o '?' en una petición ICAP, como se demuestra con el uso del método OPTIONS."
    }
  ],
  "lastModified": "2026-06-17T00:01:54.167",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:c-icap_project:c-icap:0.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "62ECD92E-0FE9-410D-BE2B-CA4E66E2BA0B"
            },
            {
              "criteria": "cpe:2.3:a:c-icap_project:c-icap:0.2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C880C071-755A-445C-B6F2-101B71AEFF67"
            },
            {
              "criteria": "cpe:2.3:a:c-icap_project:c-icap:0.2.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1B44F195-A81B-45E3-94FD-B7C911CA7986"
            },
            {
              "criteria": "cpe:2.3:a:c-icap_project:c-icap:0.2.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0DAF4657-62C5-48FF-BF57-2F837DE2876E"
            },
            {
              "criteria": "cpe:2.3:a:c-icap_project:c-icap:0.2.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "90C29B65-0B12-4DD7-A0E7-DB5C7A7CBCC0"
            },
            {
              "criteria": "cpe:2.3:a:c-icap_project:c-icap:0.2.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3CBD573D-85A0-438D-BE5A-8F672F5B961D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}